🔐 CVE Alert

CVE-2026-75133

HIGH 7.5

Keep Backup Daily WordPress Plugin < 2.1.4 Sensitive Information Exposure via kbd_cron_process

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

Keep Backup Daily plugin for WordPress before 2.1.4 contains a sensitive information exposure vulnerability that allows unauthenticated attackers to trigger a full MySQL database dump by accessing the publicly exposed `kbd_cron_process` parameter without authentication. Attackers can predict the partially predictable dump filename based on the database name, a limited random range, and the current Unix timestamp to download the generated backup from the publicly accessible uploads directory.

CWE CWE-306
Vendor fahad mahmood
Product keep backup daily
Published Aug 31, 2026
Last Updated Aug 31, 2026
Stay Ahead of the Next One

Get instant alerts for fahad mahmood keep backup daily

Be the first to know when new high vulnerabilities affecting fahad mahmood keep backup daily are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

Fahad Mahmood / Keep Backup Daily
0 < 2.1.4

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordpress.org: https://wordpress.org/plugins/keep-backup-daily/#developers vulncheck.com: https://www.vulncheck.com/advisories/keep-backup-daily-wordpress-plugin-sensitive-information-exposure-via-kbd-cron-process

Credits

Elymaro (Aurélien Bourdois)