CVE-2026-86828
BackWPup < 5.7.7 - Admin+ Path Traversal to RCE via Restore PclZip Fallback
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The BackWPup WordPress plugin before 5.7.7 does not properly restrict the destination path of files extracted during a backup restore when its fallback archive library is used, allowing high-privileged users to write files outside the intended restore directory, potentially leading to remote code execution.
| Vendor | unknown |
| Product | backwpup |
| Published | Oct 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown backwpup
Be the first to know when new unknown vulnerabilities affecting unknown backwpup are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / BackWPup
0 < 5.7.7
References
Credits
Bhaveshkumar Parmar WPScan