OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-97197

HIGH · CVSS 7.5 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

WordPress versions up to 1.6.0 are susceptible to an unauthenticated broken access control vulnerability in the Backup & Migration feature, allowing attackers to access sensitive data without authentication. This flaw could lead to unauthorized data exposure or manipulation, posing a significant risk to site integrity and user privacy. WordPress administrators and users of the affected plugin should prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-97197
Severity
HIGH
CVSS
7.5
EPSS
0.29%
WordPress

Original NVD Description

Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions.