๐Ÿ” CVE Alert

CVE-2026-86828

UNKNOWN 0.0

BackWPup < 5.7.7 - Admin+ Path Traversal to RCE via Restore PclZip Fallback

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The BackWPup WordPress plugin before 5.7.7 does not properly restrict the destination path of files extracted during a backup restore when its fallback archive library is used, allowing high-privileged users to write files outside the intended restore directory, potentially leading to remote code execution.

Vendor unknown
Product backwpup
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for unknown backwpup

Be the first to know when new unknown vulnerabilities affecting unknown backwpup are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / BackWPup
0 < 5.7.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/be8c0eab-1874-4490-b94e-394f62a522f3/

Credits

Bhaveshkumar Parmar WPScan