Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-9834— WP Database Backup <= 7.11 - Authenticated (Administrator+) OS Command Injection via 'wp_db_exclude_table' Parameter

CVSS 7.2 · High EPSS 1.54% · P73

Affected Version Matrix 1

Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-9834

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
WP Database Backup <= 7.11 - Authenticated (Administrator+) OS Command Injection via 'wp_db_exclude_table' Parameter
Source: CVE Program / CVE List V5
Vulnerability Description
The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to OS Command Injection in all versions up to and including 7.11 via the `wp_db_exclude_table` parameter. This is due to the direct concatenation of user-supplied `$_POST['wp_db_exclude_table']` values into the `mysqldump` shell command string in the `mysqldump()` function of `includes/admin/class-wpdb-admin.php` without wrapping them in `escapeshellarg()`—every other argument in the same command (DB_USER, DB_PASSWORD, host, filename, DB_NAME) is properly escaped, making the exclude-table values the sole exception—and because the only applied filtering, `sanitize_text_field()` via `recursive_sanitize_text_field()`, strips HTML tags but leaves shell metacharacters such as `;`, `|`, `` ` ``, and `$()` intact. This makes it possible for authenticated attackers, with administrator-level access and above, to execute arbitrary operating system commands on the server, potentially enabling full remote code execution. The injection is stored: malicious values submitted through the plugin settings form are persisted to the WordPress options table via `update_option('wp_db_exclude_table')` and later retrieved with `get_option()` and passed unsanitized to `shell_exec()` whenever a backup operation runs.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
在命令中使用的特殊元素转义处理不恰当(命令注入)
Source: CVE Program / CVE List V5
Vulnerability Title
WordPress WP Database Backup 命令注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
WordPress WP Database Backup是WordPress基金会的一款数据库备份插件。 WordPress WP Database Backup 7.11及之前版本存在命令注入漏洞,该漏洞源于对`wp_db_exclude_table`参数处理不当,将用户提供的值直接拼接到`mysqldump` shell命令字符串中,而未使用`escapeshellarg()`进行转义,且过滤函数`sanitize_text_field()`仅去除HTML标签但保留shell元字符,可能导致认证的攻击
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
databasebackupWP Database Backup – Unlimited Database & Files Backup by Backup for WP 0 ~ 7.11 -

II. Public POCs for CVE-2026-9834

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-9834

登录查看更多情报信息。

Patches & Fixes for CVE-2026-9834 (1)

Vendor Advisories for CVE-2026-9834 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-9834

No comments yet


Leave a comment