Executive brief
The WP Database Backup plugin for WordPress, which is used to automate website backups, contains a security flaw that allows administrators to execute unauthorized commands on the underlying web server. By submitting specially crafted text in the plugin's settings, an attacker with high-level access can take full control of the server or disrupt website operations. This could lead to a complete compromise of the website's data and the server it resides on.
Technical details
The vulnerability is a stored OS Command Injection located in the `mysqldump()` function within `includes/admin/class-wpdb-admin.php`. The plugin fails to use `escapeshellarg()` on the user-supplied `wp_db_exclude_table` parameter before concatenating it into a `shell_exec()` call for the `mysqldump` command. While other parameters are properly escaped, this specific field only undergoes `sanitize_text_field()`, which removes HTML but permits shell metacharacters like semicolons and backticks. An authenticated attacker with administrator privileges can save a malicious payload to the WordPress options table, which is subsequently executed whenever a backup process is triggered.
Affected products
- databasebackup WP Database Backup – Unlimited Database & Files Backup by Backup for WP <= 7.11
Timeline
- 2026-07-02: disclosed
- 2026-07-02: advisory
References
- https://plugins.trac.wordpress.org/browser/wp-database-backup/tags/7.10/includes/admin/class-wpdb-admin.php
- https://plugins.trac.wordpress.org/browser/wp-database-backup/tags/7.10/includes/admin/class-wpdb-admin.php
- https://plugins.trac.wordpress.org/browser/wp-database-backup/tags/7.10/includes/admin/class-wpdb-admin.php
- https://plugins.trac.wordpress.org/browser/wp-database-backup/tags/7.11/includes/admin/class-wpdb-admin.php
- https://plugins.trac.wordpress.org/browser/wp-database-backup/tags/7.11/includes/admin/class-wpdb-admin.php
- https://plugins.trac.wordpress.org/browser/wp-database-backup/tags/7.11/includes/admin/class-wpdb-admin.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3574273%40wp-database-backup&new=3574273%40wp-database-backup&sfp_email=&sfph_mail=