Is there a way this can be modified so that file manipulation permissions can be set by user, and not be global for every WP user in a multi-user blog with different levels of privilege?
Where is the security fix? When is the updated code going to be released?
I was unable to get the password protection to work, had to disable it for the backup scripts (left it on for the restore). The variable simply did not appear to be passed to the php scripts called.
allusion: your suggestion worked (I had the same problem, with DOCUMENT_ROOT pointing somewhere else (shared server environment).