Junglewise Threat Intelligence

CVE-2026-9834: Backup for WP WP Database Backup OS command injection in mysqldump

CVE-2026-9834 · Severity: high · CVSS 7.2 · Published 2026-07-02

Executive brief

The WP Database Backup plugin for WordPress, which is used to automate website backups, contains a security flaw that allows administrators to execute unauthorized commands on the underlying web server. By submitting specially crafted text in the plugin's settings, an attacker with high-level access can take full control of the server or disrupt website operations. This could lead to a complete compromise of the website's data and the server it resides on.

Technical details

The vulnerability is a stored OS Command Injection located in the `mysqldump()` function within `includes/admin/class-wpdb-admin.php`. The plugin fails to use `escapeshellarg()` on the user-supplied `wp_db_exclude_table` parameter before concatenating it into a `shell_exec()` call for the `mysqldump` command. While other parameters are properly escaped, this specific field only undergoes `sanitize_text_field()`, which removes HTML but permits shell metacharacters like semicolons and backticks. An authenticated attacker with administrator privileges can save a malicious payload to the WordPress options table, which is subsequently executed whenever a backup process is triggered.

Affected products

  • databasebackup WP Database Backup – Unlimited Database & Files Backup by Backup for WP <= 7.11

Timeline

  • 2026-07-02: disclosed
  • 2026-07-02: advisory

References