CVE-2025-24651

WordPress WebToffee WP Backup and Migration plugin <= 1.5.3 - Sensitive Data Exposure vulnerability

Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration allows Retrieve Embedded Sensitive Data. This issue affects WordPress Backup & Migration: from n/a through 1.5.3.


We have discovered 78 live websites that are affected by CVE-2025-24651.

Run a Free Instant Scan




Affected Software

Product  Wp Migration Duplicator
Category Wordpress Plugins
Vulnerable Domains78 live websites (100% of Wp Migration Duplicator install base)
Vulnerable Versions
  • from 0 through 1.5.3
Vulnerable Versions Count6 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-532 Insertion of Sensitive Information into Log File



Details

  • Published - Apr 17, 2025
  • Updated - Apr 17, 2025

Credits

  • savphill (Patchstack Alliance) (finder)

Website Distribution by Country

Number of websites using CVE-2025-24651
United States13 websites



Germany16 websites
France5 websites
Spain4 websites
Italy4 websites
Sweden3 websites
Australia2 websites
Brazil2 websites
Switzerland2 websites
GB2 websites

Website Distribution by TLD

Number of websites using CVE-2025-24651
.com20 websites
.de11 websites
.org5 websites
.se3 websites
.co.uk2 websites
.com.au2 websites
.net2 websites
.fr2 websites
.it2 websites
.be1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-24651

Top websites that are affected by CVE-2025-24651. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com Japan*,***,***
*********.com Russia*,***,***
***************.org Spain*,***,***
**********.org United States*,***,***
**********.***.au Australia*,***,***
***************.website United States*,***,***
*******.************.net *,***,***
***.ee Estonia**,***,***
*******.com Germany**,***,***
********.ee United States**,***,***
See full domain list

FAQ

CVE-2025-24651 is Insertion of Sensitive Information into Log File in Wp Migration Duplicator
A total of 78 websites have been identified as vulnerable to CVE-2025-24651, based on global website indexing conducted by WebTechSurvey.
The Wp Migration Duplicator is affected by the CVE-2025-24651 vulnerability.
Wp Migration Duplicator versions up to and including 1.5.3 are vulnerable to CVE-2025-24651.