CVE-2025-62992: WordPress Everest Backup plugin <= 2.3.11 - Cross Site Request Forgery (CSRF) vulnerability
Published Dec 31, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in everestthemes Everest Backup everest-backup allows Path Traversal.This issue affects Everest Backup: from n/a through <= 2.3.11.
Affected Software
2 affected components
wordpress/everest-backup<=2.3.9
everestthemes Everest Backup Wordpress<=2.3.9
Event History
Dec 31, 2025
CVE Published
via MITRE·08:59 AM
Data Sourced
via MITRE·08:59 AM
DescriptionWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-62992?
CVE-2025-62992 is classified as a high-severity Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2025-62992?
To mitigate CVE-2025-62992, update the Everest Backup plugin to a version above 2.3.9.
3
What versions of Everest Backup are affected by CVE-2025-62992?
CVE-2025-62992 affects all versions of Everest Backup from n/a through 2.3.9.
4
What impact does CVE-2025-62992 have on my website?
CVE-2025-62992 allows attackers to exploit CSRF attacks, potentially leading to unauthorized actions on behalf of authenticated users.
5
Is there a known exploit for CVE-2025-62992?
Yes, there are reported methods for exploiting CVE-2025-62992 that can lead to significant security risks.