Description
The WP BackItUp Community Edition plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.1.0 via the 'backup_file' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The basename() normalization present in the handler only executes when the traversed target path does not exist, providing no protection against reads of existing files.
Published: 2026-09-10
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authenticated Directory Traversal leading to arbitrary file read
Action: Update Plugin
AI Analysis

Impact

The WP BackItUp Community Edition plugin contains a directory traversal flaw in the backup_file parameter. An attacker who has administrator privileges or higher can craft a request that includes path traversal sequences, resulting in the plugin reading the contents of any file that exists on the server. This flaw allows the attacker to expose sensitive information located in server files, including configuration, database credentials, or personal user data, thereby compromising confidentiality. The weakness is a classic file system traversal (CWE-22).

Affected Systems

All WordPress installations that use WP BackItUp Community Edition version 2.1.0 or earlier are affected. Any site running a vulnerable plugin version is susceptible if an administrator account can be accessed.

Risk and Exploitability

The CVSS score is 4.9, indicating moderate risk. No EPSS score is supplied and the vulnerability is not listed in CISA's KEV catalog. An attacker must already have authenticated administrator access to exploit the flaw. Because the attacker can read arbitrary existing files, the severity depends on the sensitivity of the files available on the host but the overall impact remains moderate as authenticated access can be limited in many environments. The exploitation requires only the misuse of the backup_file endpoint and no external network entry point beyond normal WordPress administrative traffic.

Generated by OpenCVE AI on September 10, 2026 at 05:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to WP BackItUp Community Edition version newer than 2.1.0
  • Restrict administrator accounts to the minimum necessary users and enforce least privilege
  • Disable or modify the backup_file parameter handling to enforce strict path validation or remove the endpoint altogether

Generated by OpenCVE AI on September 10, 2026 at 05:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Cssimmon
Cssimmon wp Backitup Community Edition
Wordpress
Wordpress wordpress
Vendors & Products Cssimmon
Cssimmon wp Backitup Community Edition
Wordpress
Wordpress wordpress

Thu, 10 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Description The WP BackItUp Community Edition plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.1.0 via the 'backup_file' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The basename() normalization present in the handler only executes when the traversed target path does not exist, providing no protection against reads of existing files.
Title WP BackItUp Community Edition <= 2.1.0 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'backup_file' Parameter
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Cssimmon Wp Backitup Community Edition
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-10T21:00:26.535Z

Reserved: 2026-07-30T12:57:05.405Z

Link: CVE-2026-18386

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-10T04:17:48.437

Modified: 2026-09-10T21:17:23.503

Link: CVE-2026-18386

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:09:40Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')