Impact
The BackupSheep WordPress Backup Plugin up to version 1.8 fails to validate its integration key, treating an unset or blank key as authentic. This flaw lets an attacker without any credentials trigger a backup process, download a complete site archive—including the database containing user password hashes—and delete arbitrary files on the server. The breach results in loss of confidentiality, integrity, and availability at the site level, allowing an attacker to exfiltrate sensitive data and maintain persistent control over the system.
Affected Systems
All installations of the BackupSheep WordPress Backup Plugin version 1.8 or earlier are vulnerable; the plugin was listed on WordPress.org until July 2024 and has since been removed, with no fixed or patched version released.
Risk and Exploitability
The CVSS score is 10.0, indicating a total impact if exploited, while the EPSS score is not available and the vulnerability is not yet listed in the CISA KEV catalog. Because the flaw permits unauthenticated access via the plugin’s web interface, an attacker could obtain full site backups and delete files with no prerequisite credentials. The absence of a vendor fix and the high severity rating make this a critical risk that warrants immediate action until the plugin is replaced or removed.
OpenCVE Enrichment