CVE-2026-9834
databasebackup WP Database Backup – Unlimited Database & Files Backup by Backup for WP
The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to OS Command Injection in all versions up to and including 7.11 via the `wp_db_exclude_table` parameter. This is due to the direct concatenation of user-supplied `$_POST['wp_db_exclude_table']` values into the `mysqldump` shell command string in the `mysqldump()` function of `includes/admin/class-wpdb-admin.php` without wrapping them in `escapeshellarg()`—every other argument in the same command (DB_USER, DB_PASSWORD, host, filename, DB_NAME) is properly escaped, making the exclud...
- CVSS
- 7.2
- EPSS
- 1.59% 72.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.02