CVE-2026-86827
BackWPup 3.3 - 5.7.6 - Unauthenticated Backup Job Execution via wp-cron.php
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The BackWPup WordPress plugin before 5.7.7 does not verify that a request to its cron-triggered backup execution handler actually originates from WordPress's internal scheduled-event dispatch, allowing unauthenticated attackers to force any existing backup job to run immediately, independent of its configured trigger type or schedule.
| Vendor | unknown |
| Product | backwpup |
| Published | Oct 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown backwpup
Be the first to know when new unknown vulnerabilities affecting unknown backwpup are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / BackWPup
3.3 < 5.7.7
References
Credits
Duy Tran WPScan