CVE-2025-24651: WordPress WebToffee WP Backup and Migration plugin <= 1.5.3 - Sensitive Data Exposure vulnerability
Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration wp-migration-duplicator allows Retrieve Embedded Sensitive Data.This issue affects WordPress Backup & Migration: from n/a through <= 1.5.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24651?
The severity of CVE-2025-24651 is classified as medium due to the potential exposure of sensitive data.
How do I fix CVE-2025-24651?
To fix CVE-2025-24651, upgrade your WebToffee WordPress Backup & Migration plugin to the latest version beyond 1.5.3.
What types of sensitive information are impacted by CVE-2025-24651?
CVE-2025-24651 impacts sensitive information that may be inadvertently logged during the backup and migration process in WordPress.
Can CVE-2025-24651 lead to data breaches?
Yes, if exploited, CVE-2025-24651 can lead to data breaches by allowing unauthorized access to sensitive information in log files.
Is CVE-2025-24651 specific to certain versions of the plugin?
Yes, CVE-2025-24651 affects WebToffee WordPress Backup & Migration versions up to and including 1.5.3.