Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 01 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Inisev
Inisev backup Migration Wordpress Wordpress wordpress |
|
| Vendors & Products |
Inisev
Inisev backup Migration Wordpress Wordpress wordpress |
Mon, 24 Nov 2025 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 24 Nov 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Backup Migration WordPress plugin before 2.0.0 does not properly generate its backup path in certain server configurations, allowing unauthenticated users to fetch a log that discloses the backup filename. The backup archive is then downloadable without authentication. | |
| Title | Backup Migration < 2.0.0 - Unauthenticated Backup Download | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-11-24T10:54:28.331Z
Reserved: 2025-10-28T13:37:23.478Z
Link: CVE-2025-12394
Updated: 2025-11-24T10:54:17.983Z
Status : Deferred
Published: 2025-11-24T06:15:45.923
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-12394
No data.
OpenCVE Enrichment
Updated: 2025-12-01T15:19:14Z
No weakness.