CVE-2026-86827
Received Received - Intake

Unauthenticated Backup Job Execution in BackWPup WordPress Plugin

Vulnerability report for CVE-2026-86827, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: WPScan

Description

The BackWPup WordPress plugin before 5.7.7 does not verify that a request to its cron-triggered backup execution handler actually originates from WordPress's internal scheduled-event dispatch, allowing unauthenticated attackers to force any existing backup job to run immediately, independent of its configured trigger type or schedule.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown BackWPup 3.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the BackWPup WordPress plugin versions 3.3 to 5.7.6. It allows unauthenticated attackers to force any existing backup job to run immediately by exploiting a flaw in the plugin's cron-triggered backup execution handler. The plugin does not verify if requests originate from WordPress's internal scheduled-event dispatch, enabling unauthorized execution of backup jobs regardless of their configured schedule or trigger type.

Detection Guidance

Check the installed version of the BackWPup plugin in your WordPress admin panel. If it is between 3.3 and 5.7.6, the system is vulnerable. Look for unexpected backup job executions in logs or server activity.

Impact Analysis

Unauthenticated attackers could force backup jobs to run at any time, potentially causing unexpected server load, resource consumption, or interference with legitimate scheduled backups. This may disrupt normal operations and lead to performance issues or downtime on the affected WordPress site.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized access to backup data. If attackers force backup jobs to run, they may exfiltrate sensitive data stored in backups, violating data protection requirements under GDPR (e.g., unauthorized access) and HIPAA (e.g., integrity and confidentiality of protected health information).

Mitigation Strategies

Update the BackWPup plugin to version 5.7.7 or later immediately. If updating is not possible, disable the plugin until the update is applied to prevent unauthorized backup executions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86827. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart