CVE-2026-86828
Received Received - Intake

BackWPup Plugin Path Traversal Vulnerability

Vulnerability report for CVE-2026-86828, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: WPScan

Description

The BackWPup WordPress plugin before 5.7.7 does not properly restrict the destination path of files extracted during a backup restore when its fallback archive library is used, allowing high-privileged users to write files outside the intended restore directory, potentially leading to remote code execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown BackWPup 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a path traversal issue in the BackWPup WordPress plugin versions before 5.7.7. When using the fallback archive library (PclZip), authenticated admin users can write files outside the intended restore directory during backup restoration. This may allow remote code execution.

Detection Guidance

Check the installed version of BackWPup plugin using WordPress admin panel or via command line. Look for versions prior to 5.7.7. Review backup restore logs for unexpected file writes outside intended directories.

Impact Analysis

If exploited, this vulnerability could allow an attacker with admin access to execute arbitrary code on your server. This might lead to full system compromise, data theft, or further attacks within your WordPress environment.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized file writes outside intended directories. High-privileged users exploiting this flaw might access or modify sensitive data improperly, violating data protection requirements under these regulations.

Mitigation Strategies

Update BackWPup plugin to version 5.7.7 or later immediately. Restrict administrative user access to only necessary personnel. Monitor file system changes during backup restores.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86828. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart