๐Ÿ” CVE Alert

CVE-2026-101148

UNKNOWN 0.0

BackupSheep <= 1.8 - Unauthenticated Arbitrary File Deletion and Backup Exfiltration via Empty Integration Key

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, including the database with user password hashes, and to delete arbitrary files on the server, leading to sensitive data disclosure and site takeover. The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 has been closed on WordPress.org since July 2024 and no fixed version is available. Remove it from any site where it is installed.

Vendor unknown
Product backupsheep wordpress backup plugin
Published Oct 1, 2026
Stay Ahead of the Next One

Get instant alerts for unknown backupsheep wordpress backup plugin

Be the first to know when new unknown vulnerabilities affecting unknown backupsheep wordpress backup plugin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / BackupSheep WordPress Backup Plugin
0 โ‰ค 1.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/5d6fce13-34e3-4ec6-9b47-a78dd7c94fed/

Credits

Enrico Marcolini Claudio Marchesini Dottor Marc WPScan