Path Traversal Vulnerability in Worry Proof Backup Plugin for WordPress
CVE-2026-1311
8.8HIGH
What is CVE-2026-1311?
The Worry Proof Backup plugin for WordPress allows authenticated attackers, with Subscriber-level access and above, to exploit a path traversal flaw through its backup upload functionality. This vulnerability enables the upload of a malicious ZIP archive containing path traversal sequences, which can lead to the writing of arbitrary files on the server. Attackers may utilize this vulnerability to create and execute unauthorized PHP files, leading to potential remote code execution.
Affected Version(s)
Worry Proof Backup 0 <= 0.2.4