CVE-2019-25224: Wpseeds Wp Database Backup
Critical severity, CVSS 9.8. EPSS: 21.4% chance of exploitation in the next 30 days.
The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticated attackers to execute arbitrary commands on the host operating system.
Affected products
- Wpseeds Wp Database Backup: before 5.2 (fixed in 5.2)
Published 2025-07-25. Last modified 2026-06-17.