CVE-2025-28954 Information

Description

Cross-Site Request Forgery (CSRF) vulnerability in wphobby Backwp allows Path Traversal. This issue affects Backwp: from n/a through 2.0.2.

Reference

https://patchstack.com/database/wordpress/plugin/backwp/vulnerability/wordpress-backwp-plugin-2-0-2-csrf-to-arbitrary-file-deletion-vulnerability?_s_id=cve

Share on: