CVE-2026-86815
BackWPup 5.2.2 - 5.7.4 - BackWPup Jobs Checker+ Database Backup Exfiltration via Missing Authorization on Job REST Routes
CVSS Score
5.5
EPSS Score
0.0%
EPSS Percentile
0th
The BackWPup WordPress plugin before 5.7.5 does not properly restrict access to several of its REST API routes for job, backup-destination, and backup-execution management, allowing users holding a BackWPup WordPress plugin before 5.7.5-defined, administrator-assigned limited role to create and run backup jobs and exfiltrate a full database backup to an attacker-controlled destination.
| Vendor | unknown |
| Product | backwpup |
| Published | Sep 11, 2026 |
| Last Updated | Sep 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown backwpup
Be the first to know when new medium vulnerabilities affecting unknown backwpup are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / BackWPup
5.2.2 < 5.7.5
References
Credits
Charles Vosburgh WPScan