CSRF Vulnerability in UpdraftPlus Backup Plugin for WordPress
CVE-2026-76549

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 August 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-76549?

The UpdraftPlus: WP Backup & Migration Plugin for WordPress, prior to version 1.26.7, lacks proper CSRF checks in a critical backup management operation. This vulnerability can potentially allow an attacker to trick an authenticated admin into restoring a backup without their consent, effectively reverting the website's database and files to a prior state. By employing a specially crafted link, malicious actors can exploit this security flaw to gain unauthorized control over backup restorations.

Affected Version(s)

UpdraftPlus: WP Backup & Migration Plugin 0 < 1.26.7

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jashid Sany
WPScan
.