CyberRota Analysis
AI-GeneratedWordPress versions up to 1.6.0 are susceptible to an unauthenticated broken access control vulnerability in the Backup & Migration feature, allowing attackers to access sensitive data without authentication. This flaw could lead to unauthorized data exposure or manipulation, posing a significant risk to site integrity and user privacy. WordPress administrators and users of the affected plugin should prioritize immediate updates to mitigate potential exploitation.
CVE
CVE-2026-97197
Severity
HIGH
CVSS
7.5
EPSS
0.29%
WordPress
Original NVD Description
Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions.