File Extraction Vulnerability in BackWPup Plugin by WordPress
CVE-2026-86828
Key Information:
Badges
What is CVE-2026-86828?
The BackWPup plugin for WordPress prior to version 5.7.7 has a security flaw that fails to adequately restrict the destination path for files extracted during backup restores. This issue arises when the fallback archive library is utilized, allowing high-privileged users to manipulate the backup process and write files outside the designated restore directory. As a consequence, this vulnerability may lead to unauthorized file access and potentially enable remote code execution, posing a significant security risk to affected WordPress installations.
Affected Version(s)
BackWPup 0 < 5.7.7
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.