Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

Backup Migration Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 17 vulnerability records associated with Backup Migration, published between 2021 and 2026.

Dataset last synchronized: 2026-08-02 09:41:47 UTC

At a glance

Security Snapshot

17Total records
3Critical
6High
8Medium
0Low
0Informational
17Patched records
0Currently marked unpatched
2021-11-17First disclosure
2026-04-08Latest disclosure
16 of 17CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
202111 records
20231010 records
202422 records
202522 records
202622 records

Severity Breakdown

SeverityRecordsShare
Critical317.6%
High635.3%
Medium847.1%

Vulnerability-Type Breakdown

Information Disclosure

6 records35.3%

First: 2023. Latest: 2026.

Other

4 records23.5%

First: 2023. Latest: 2025.

Missing Authorization

3 records17.6%

First: 2023. Latest: 2026.

CSRF

2 records11.8%

First: 2023. Latest: 2023.

Cross-Site Scripting

1 record5.9%

First: 2021. Latest: 2021.

Path Traversal

1 record5.9%

First: 2023. Latest: 2023.

Patch Status

Patched
17
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 2.1.2
  • 2.1.0
  • 2.0.0
  • 1.4.6.1
  • 1.4.4
  • 1.4.2
  • 1.4.0
  • 1.3.8
  • 1.3.6
  • 1.3.7
  • 1.3.0
  • 1.2.8
  • 1.2.9
  • 1.1.6

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-2.1.1BackupBliss – Backup & Migration with Free Cloud Storage <= 2.1.1 - Unauthenticated Information ExposureApril 8, 20262.1.2Medium
*-2.0.0Backup Migration <= 2.0.0 - Missing Authorization to Unauthenticated Backup Upload to Offline StorageApril 6, 20262.1.0Medium
*-1.4.9Backup Migration <= 1.4.9 - Information Exposure to Unauthenticated Back-up DownloadNovember 3, 20252.0.0High
*-1.4.6Backup Migration <= 1.4.6 - Unauthenticated PHP Object Injection via 'recursive_unserialize_replace'January 3, 20251.4.6.1High
*-1.4.3Backup Migration <= 1.4.3 - Information Exposure via Log FilesApril 17, 20241.4.4Medium
*-1.4.1Inisev Analyst Module <= Various Versions - Missing AuthorizationApril 10, 20241.4.2Medium
*-1.3.9Backup Migration <= 1.3.9 - Authenticated (Admin+) OS Command Injection via urlDecember 22, 20231.4.0High
1.0.8-1.3.9Backup Migration 1.0.8 - 1.3.9 - Remote File Inclusion via content-dirDecember 22, 20231.4.0High
*-1.3.9Backup Migration <= 1.3.9 - Unauthenticated Path Traversal to Arbitrary File DeletionDecember 22, 20231.4.0Critical
*-1.3.7Backup Migration <= 1.3.7 - Unauthenticated Remote Code ExecutionDecember 11, 20231.3.8Critical
*-1.3.5Backup Migration <= 1.3.5 - Unauthenticated Sensitive Information ExposureDecember 7, 20231.3.6Critical
*-1.3.6Backup Migration <= 1.3.6 - Unauthenticated Arbitrary Backup Download to Sensitive Information ExposureNovember 30, 20231.3.7High
[*, 1.3.0)Backup Migration <= 1.2.9 - Cross-Site Request ForgerySeptember 5, 20231.3.0Medium
*-1.2.7Inisev Plugins (Various Versions) - Missing Authorization on handle_installation functionJuly 27, 20231.2.8Medium
*-1.2.7Inisev Plugins (Various Versions) - Cross-Site Request Forgery on handle_installation functionJuly 27, 20231.2.8Medium
*-1.2.8Backup Migration <= 1.2.8 - Sensitive Information ExposureMay 10, 20231.2.9High
*-1.1.5Backup Migration <= 1.1.5 - Authenticated (Admin+) Stored Cross-Site ScriptingNovember 17, 20211.1.6Medium

Selected source records

Latest Records

MediumCVE-2026-39480

BackupBliss – Backup & Migration with Free Cloud Storage <= 2.1.1 - Unauthenticated Information Exposure

Published: April 8, 2026

Affected versions
*-2.1.1
Patched versions
2.1.2
Original Wordfence record
MediumCVE-2025-14944

Backup Migration <= 2.0.0 - Missing Authorization to Unauthenticated Backup Upload to Offline Storage

Published: April 6, 2026

Affected versions
*-2.0.0
Patched versions
2.1.0
Original Wordfence record
HighCVE-2025-12394

Backup Migration <= 1.4.9 - Information Exposure to Unauthenticated Back-up Download

Published: November 3, 2025

Affected versions
*-1.4.9
Patched versions
2.0.0
Original Wordfence record
HighCVE-2024-10932

Backup Migration <= 1.4.6 - Unauthenticated PHP Object Injection via 'recursive_unserialize_replace'

Published: January 3, 2025

Affected versions
*-1.4.6
Patched versions
1.4.6.1
Original Wordfence record
MediumCVE-2024-32686

Backup Migration <= 1.4.3 - Information Exposure via Log Files

Published: April 17, 2024

Affected versions
*-1.4.3
Patched versions
1.4.4
Original Wordfence record
MediumCVE-2024-31435

Inisev Analyst Module <= Various Versions - Missing Authorization

Published: April 10, 2024

Affected versions
*-3.2.6
Patched versions
3.2.7
Affected versions
*-1.4.4
Patched versions
1.4.5
Affected versions
*-3.6.1
Patched versions
3.6.2
Affected versions
*-2.2.9
Patched versions
2.3.0
Affected versions
*-1.4.1
Patched versions
1.4.2
Affected versions
*-1.2.3
Patched versions
1.2.4
Affected versions
*-1.1.9
Patched versions
1.2.0
Affected versions
*-2.4.3
Patched versions
2.4.4
Affected versions
*-3.9
Patched versions
4.0
Affected versions
*-2.8.6
Patched versions
2.8.7
Affected versions
*-1.6.4
Patched versions
1.6.5
Original Wordfence record
CriticalCVE-2023-6972

Backup Migration <= 1.3.9 - Unauthenticated Path Traversal to Arbitrary File Deletion

Published: December 22, 2023

Affected versions
*-1.3.9
Patched versions
1.4.0
Original Wordfence record
HighCVE-2023-6971

Backup Migration 1.0.8 - 1.3.9 - Remote File Inclusion via content-dir

Published: December 22, 2023

Affected versions
1.0.8-1.3.9
Patched versions
1.4.0
Original Wordfence record

Highest-Severity Records

CriticalCVE-2023-6972

Backup Migration <= 1.3.9 - Unauthenticated Path Traversal to Arbitrary File Deletion

Published: December 22, 2023

Affected versions
*-1.3.9
Patched versions
1.4.0
Original Wordfence record
CriticalCVE-2023-6553

Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution

Published: December 11, 2023

Affected versions
*-1.3.7
Patched versions
1.3.8
Original Wordfence record
CriticalCVE-2023-6271

Backup Migration <= 1.3.5 - Unauthenticated Sensitive Information Exposure

Published: December 7, 2023

Affected versions
*-1.3.5
Patched versions
1.3.6
Original Wordfence record
HighCVE-2024-10932

Backup Migration <= 1.4.6 - Unauthenticated PHP Object Injection via 'recursive_unserialize_replace'

Published: January 3, 2025

Affected versions
*-1.4.6
Patched versions
1.4.6.1
Original Wordfence record
HighCVE-2023-6971

Backup Migration 1.0.8 - 1.3.9 - Remote File Inclusion via content-dir

Published: December 22, 2023

Affected versions
1.0.8-1.3.9
Patched versions
1.4.0
Original Wordfence record
HighCVE-2023-6266

Backup Migration <= 1.3.6 - Unauthenticated Arbitrary Backup Download to Sensitive Information Exposure

Published: November 30, 2023

Affected versions
*-1.3.6
Patched versions
1.3.7
Original Wordfence record
HighCVE-2025-12394

Backup Migration <= 1.4.9 - Information Exposure to Unauthenticated Back-up Download

Published: November 3, 2025

Affected versions
*-1.4.9
Patched versions
2.0.0
Original Wordfence record
HighCVE-2023-54346

Backup Migration <= 1.2.8 - Sensitive Information Exposure

Published: May 10, 2023

Affected versions
*-1.2.8
Patched versions
1.2.9
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory