WordPress Backup Guard plugin before 1.6.0 is susceptible to authenticated arbitrary file upload. The plugin does not ensure that imported files are in SGBP format and extension, allowing high-privilege users to upload arbitrary files, including PHP, possibly leading to remote code execution.
id: CVE-2021-24155
info:
name: WordPress BackupGuard <1.6.0 - Authenticated Arbitrary File Upload
...