Stored Cross-Site Scripting Vulnerability in Keep Backup Daily Plugin for WordPress
CVE-2026-3577

4.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
20 March 2026

What is CVE-2026-3577?

The Keep Backup Daily plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability via the backup title alias in the update_kbd_bkup_alias AJAX action. This issue arises from inadequate input sanitization and lack of proper HTML output escaping, allowing authenticated attackers with Administrator-level access to inject and execute arbitrary web scripts. The vulnerability exploits the absence of encoding for double quotes and outputs backup titles in HTML attribute contexts without secure escaping functions. As a result, any administrator can fall victim to this attack when viewing the backup list page, thereby compromising the security of the website.

Affected Version(s)

Keep Backup Daily 0 <= 2.1.2

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

san6051
.