Unauthenticated Site Backup Issues in BackupSheep WordPress Plugin
CVE-2026-101148
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 October 2026
Badges
What is CVE-2026-101148?
The BackupSheep WordPress Backup Plugin, prior to version 1.8, fails to impose adequate validation checks on its integration key, mistakenly allowing an unset or blank key to be treated as valid. This loophole enables unauthenticated users to access sensitive functionalities, such as creating and downloading full site backups which include critical data like user password hashes from the database. Additionally, attackers could delete arbitrary files from the server, posing significant risks of sensitive data exposure and potential site takeover. As of July 2024, the BackupSheep plugin has been removed from WordPress.org, and no fix is available; users are strongly advised to uninstall it from their sites.
Affected Version(s)
BackupSheep WordPress Backup Plugin 0 <= 1.8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.