CVE-2026-19454
Received Received - Intake

JetBackup WordPress Plugin Unauthorized Full Backup Access

Vulnerability report for CVE-2026-19454, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-27

Last updated on: 2026-08-27

Assigner: WPScan

Description

The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup archives and job logs, allowing an administrator of the network's main site who is not a Super Admin to download a full backup of the entire network, including every site's data and the shared webroot.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-27
Last Modified
2026-08-27
Generated
2026-08-27
AI Q&A
2026-08-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
jetbackup jetbackup to 3.1.23.5 (exc)
jetbackup jetbackup From 3.1.18.8 (inc) to 3.1.23.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the JetBackup WordPress plugin before version 3.1.23.5 allows an administrator of the main site in a multisite network to download full backups of the entire network, including all sites' data and shared webroot. The issue occurs because the plugin does not perform proper multisite authorization checks before serving backup archives and job logs.

Detection Guidance

Check the installed version of the JetBackup WordPress plugin. If it is between 3.1.18.8 and 3.1.23.3, the system is vulnerable. Update to version 3.1.23.5 or later to resolve the issue.

Impact Analysis

An attacker with administrator access to the main site could exploit this to steal sensitive data from all sites in the network, including user information, configurations, and files. This could lead to data breaches, unauthorized access, or further attacks on other systems.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR, HIPAA, or other regulations by exposing personal or sensitive data. Unauthorized access to backups may result in data leaks, violating privacy requirements and potentially leading to legal penalties or reputational damage.

Mitigation Strategies

Immediately update the JetBackup WordPress plugin to version 3.1.23.5 or higher. Ensure that only Super Admins have administrative access to the network's main site to prevent unauthorized downloads of backups.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19454. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart