Description
The JetBackup WordPress plugin before 3.1.23.5 does not verify the role or capabilities of the account it preserves across a restore or migration before granting it administrator privileges, allowing a subscriber-level user to gain administrator access after the site owner restores or migrates the site.
Published: 2026-09-02
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Update
AI Analysis

Impact

JetBackup’s WordPress backup plugin fails to verify the role or capabilities of a user when a backup is restored or the site is migrated. As a result, a user with only subscriber-level privileges can gain administrator access upon restoration, effectively escalating privileges without authorization. The flaw directly allows a lower‑privileged user to attain full control over the website content, settings, and other user accounts.

Affected Systems

WordPress sites running the JetBackup plugin version 3.1.7.9 through 3.1.23.3 are impacted. The vendor is listed as Unknown:JetBackup. All affected instances lack the role‑verification logic that assigns only existing administrators elevated rights during a restore or migration.

Risk and Exploitability

Exploit requires the site owner or a person with restoration privileges to initiate a backup restore or migration on a site that contains a subscriber user. When the restore occurs, the plugin incorrectly assigns administrator privileges to that subscriber. The EPSS score of < 1% indicates a very low probability of exploitation, yet the vulnerability is not listed in CISA KEV. The CVSS score of 7.1 indicates medium‑high severity, but the vulnerability poses a significant threat due to the clear privilege escalation path and the ease of exploitation during routine restoration tasks. Attackers would need to reach a state where the site owner performs the restore, after which the subscriber becomes an administrator automatically.

Generated by OpenCVE AI on September 2, 2026 at 15:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update JetBackup to version 3.1.23.5 or newer where role verification during restore is implemented properly
  • If an immediate update is not feasible, temporarily disable the JetBackup plugin or restrict restore capabilities to administrators only until the patch is applied
  • Monitor audit logs for unexpected role changes after restorations and review backup permissions regularly

Generated by OpenCVE AI on September 2, 2026 at 15:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 02 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Jetbackup
Jetbackup jetbackup
Wordpress
Wordpress wordpress
Vendors & Products Jetbackup
Jetbackup jetbackup
Wordpress
Wordpress wordpress

Wed, 02 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 02 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The JetBackup WordPress plugin before 3.1.23.5 does not verify the role or capabilities of the account it preserves across a restore or migration before granting it administrator privileges, allowing a subscriber-level user to gain administrator access after the site owner restores or migrates the site.
Title JetBackup 3.1.7.9 - 3.1.23.3 - Subscriber+ Privilege Escalation via Restore Admin User Selection
References

Subscriptions

Jetbackup Jetbackup
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-02T10:45:58.440Z

Reserved: 2026-08-10T14:10:15.826Z

Link: CVE-2026-19453

cve-icon Vulnrichment

Updated: 2026-09-02T10:13:07.426Z

cve-icon NVD

Status : Deferred

Published: 2026-09-02T06:17:16.840

Modified: 2026-09-03T17:50:37.690

Link: CVE-2026-19453

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T15:45:04Z

Weaknesses
  • CWE-269

    Improper Privilege Management