OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-101148

CRITICAL · CVSS 10 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The BackupSheep WordPress Backup Plugin versions up to 1.8 are critically vulnerable due to improper validation of the integration key, allowing unauthenticated attackers to create and download complete site backups, including sensitive database information, and to delete arbitrary files on the server. This poses a severe risk of sensitive data exposure and potential site takeover. All WordPress site administrators using this plugin should prioritize its removal immediately, as no patch is available and the plugin has been removed from WordPress.org.

CVE
CVE-2026-101148
Severity
CRITICAL
CVSS
10
EPSS
0.31%
WordPress

Original NVD Description

The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, including the database with user password hashes, and to delete arbitrary files on the server, leading to sensitive data disclosure and site takeover. The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 has been closed on WordPress.org since July 2024 and no fixed version is available. Remove it from any site where it is installed.