Reflected Cross-Site Scripting Vulnerability in Royal WordPress Backup & Restore Plugin
CVE-2026-4305

6.1MEDIUM

What is CVE-2026-4305?

The Royal WordPress Backup & Restore Plugin has a reflected cross-site scripting vulnerability via the 'wpr_pending_template' parameter due to inadequate input validation. This flaw allows unauthenticated attackers to inject malicious web scripts into pages viewed by an administrator, potentially leading to significant security breaches if the administrator is tricked into executing a harmful action.

Affected Version(s)

Royal WordPress Backup, Restore & Migration Plugin – Backup WordPress Sites Safely 0 <= 1.0.16

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abi Wiranata
.