VULNERABILITY INTELLIGENCE
CVE-2019-25224
CVSS score9.8 CRITICAL
EPSS probability21.41%
CISA KEVNot currently listed
Published2025-07-25
Last modified2026-06-17
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticated attackers to execute arbitrary commands on the host operating system.
Weakness classification
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Primary references
- security@wordfence.com — Exploit, Third Party Advisory
- security@wordfence.com — Exploit, Third Party Advisory
- security@wordfence.com — Patch
- security@wordfence.com — Exploit
- security@wordfence.com — Exploit, Third Party Advisory
- security@wordfence.com — Third Party Advisory