Reflected Cross-Site Scripting Vulnerability in Royal WordPress Backup & Restore Plugin
CVE-2026-4305
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 April 2026
What is CVE-2026-4305?
The Royal WordPress Backup & Restore Plugin has a reflected cross-site scripting vulnerability via the 'wpr_pending_template' parameter due to inadequate input validation. This flaw allows unauthenticated attackers to inject malicious web scripts into pages viewed by an administrator, potentially leading to significant security breaches if the administrator is tricked into executing a harmful action.
Affected Version(s)
Royal WordPress Backup, Restore & Migration Plugin β Backup WordPress Sites Safely 0 <= 1.0.16