SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-86815

MEDIUM · CVSS 5.5 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The BackWPup plugin for WordPress versions prior to 5.7.5 has inadequate access controls on its REST API routes, enabling users with limited administrative roles to create and execute backup jobs. This vulnerability could lead to unauthorized access and exfiltration of sensitive database backups to malicious destinations. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data breaches.

CVE
CVE-2026-86815
Severity
MEDIUM
CVSS
5.5
EPSS
0.23%
WordPress

Original NVD Description

The BackWPup WordPress plugin before 5.7.5 does not properly restrict access to several of its REST API routes for job, backup-destination, and backup-execution management, allowing users holding a BackWPup WordPress plugin before 5.7.5-defined, administrator-assigned limited role to create and run backup jobs and exfiltrate a full database backup to an attacker-controlled destination.