CVE-2026-19454
Received
Received - Intake
JetBackup WordPress Plugin Unauthorized Full Backup Access
Vulnerability report for CVE-2026-19454, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-27
Last updated on: 2026-08-27
Assigner: WPScan
Description
Description
The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup archives and job logs, allowing an administrator of the network's main site who is not a Super Admin to download a full backup of the entire network, including every site's data and the shared webroot.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| jetbackup | jetbackup | to 3.1.23.5 (exc) |
| jetbackup | jetbackup | From 3.1.18.8 (inc) to 3.1.23.3 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |