Unauthenticated Site Backup Issues in BackupSheep WordPress Plugin
CVE-2026-101148

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
1 October 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-101148?

The BackupSheep WordPress Backup Plugin, prior to version 1.8, fails to impose adequate validation checks on its integration key, mistakenly allowing an unset or blank key to be treated as valid. This loophole enables unauthenticated users to access sensitive functionalities, such as creating and downloading full site backups which include critical data like user password hashes from the database. Additionally, attackers could delete arbitrary files from the server, posing significant risks of sensitive data exposure and potential site takeover. As of July 2024, the BackupSheep plugin has been removed from WordPress.org, and no fix is available; users are strongly advised to uninstall it from their sites.

Affected Version(s)

BackupSheep WordPress Backup Plugin 0 <= 1.8

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Enrico Marcolini
Claudio Marchesini
Dottor Marc
WPScan
.