Unauthorized Data Modification in WordPress Backup Plugin by Insecure Functionality
CVE-2025-15041
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 February 2026
What is CVE-2025-15041?
The BackWPup plugin for WordPress is susceptible to unauthorized data modification due to a missing capability check within the save_site_option() function. This flaw allows authenticated users with sufficient access levels to alter arbitrary options. Attackers with such access can manipulate the site's settings, including elevating user roles to administrators and circumventing user registration protocols, which can further compromise the security of the WordPress installation.
Affected Version(s)
BackWPup – WordPress Backup & Restore Plugin * <= 5.6.2