CVE-2025-11380

MEDIUM

Everest Backup - WordPress Cloud Backup, Migration, Restore & Cloni...

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-11380. PoCs published by fleetcaptain.

AI-analyzed exploit summary This PoC exploits an unauthenticated backup access vulnerability in the Everest Backup WordPress plugin by polling the admin-ajax.php endpoint to detect and download backup files. It leverages an info leak to retrieve the backup URL without authentication.

Description

The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'everest_process_status' AJAX action in all versions up to, and including, 2.3.5. This makes it possible for unauthenticated attackers to retrieve back-up file locations that can be subsequently accessed and downloaded. This does require a back-up to be running in order for an attacker to retrieve the back-up location.

Exploits (1)

nomisec WORKING POC
by fleetcaptain · poc
https://github.com/fleetcaptain/everest-backup-cve-2025-11380

This PoC exploits an unauthenticated backup access vulnerability in the Everest Backup WordPress plugin by polling the admin-ajax.php endpoint to detect and download backup files. It leverages an info leak to retrieve the backup URL without authentication.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Everest Backup WordPress plugin v2.3.5 and older
No auth needed
Prerequisites: Target must have the vulnerable Everest Backup plugin installed · Backup process must be initiated or detectable
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 5.9
EPSS 0.0037
EPSS Percentile 28.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (1)
everestthemes/Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin < 2.3.5
Published Oct 11, 2025
Tracked Since Feb 18, 2026