VULNERABILITY INTELLIGENCE

CVE-2019-25224

CVSS score9.8 CRITICAL
EPSS probability21.41%
CISA KEVNot currently listed
Published2025-07-25
Last modified2026-06-17
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticated attackers to execute arbitrary commands on the host operating system.

Weakness classification

  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Primary references