Search Results (3 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-86826 1 Wordpress-extensions 1 Backwpup 2026-10-09 5.9 Medium
The BackWPup WordPress plugin before 5.7.7 does not properly restrict web access to the working directory it uses during backup restores, allowing unauthenticated attackers, on webservers that do not honour .htaccess rules such as NGINX, to download the full backup archive (database dump and site files, including credentials and secret keys) left behind by an interrupted restore.
CVE-2026-86827 1 Wordpress-extensions 1 Backwpup 2026-10-09 5.3 Medium
The BackWPup WordPress plugin before 5.7.7 does not verify that a request to its cron-triggered backup execution handler actually originates from WordPress's internal scheduled-event dispatch, allowing unauthenticated attackers to force any existing backup job to run immediately, independent of its configured trigger type or schedule.
CVE-2026-86828 1 Wordpress-extensions 1 Backwpup 2026-10-09 6.6 Medium
The BackWPup WordPress plugin before 5.7.7 does not properly restrict the destination path of files extracted during a backup restore when its fallback archive library is used, allowing high-privileged users to write files outside the intended restore directory, potentially leading to remote code execution.