Exploiting WP Database Backup WordPress Plugin

This repo will be describe how to exploit WP Database Backup WordPress Plugin versions <=5.5

About WP Database Backup WordPress Plugin

WP Database Backup plugin helps you to create Database Backup and Restore Database Backup easily on single click. Manual or Automated Database Backups And also store database backup on safe place- Dropbox,FTP,Email,Google drive, Amazon S3.

PoC - Download Database backup

This plugin stores downloads by default locally in the directory wp-content/uploads/db-backup/ with this syntax:

[Site_Title]_[Date with EPOC]_[7 characters random ID]

This directory exposes the backup file to an unauthorized sphere of control (CWE-530) and backup files can be downloaded by unauthorized people in this way:

curl -O

For example, to list the files in the directory, you can use Bash Brace Expansion like this:


Wildcard is not supported over HTTP, however you can use bash brace expansion to guess the files in the directory.

This is a piece of the sql downloaded: