Description
The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup archives and job logs, allowing an administrator of the network's main site who is not a Super Admin to download a full backup of the entire network, including every site's data and the shared webroot.
Published: 2026-08-27
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized full network backup download exposing all sites’ data and shared webroot
Action: Immediate Patch
AI Analysis

Impact

The JetBackup plugin for WordPress fails to perform a proper multisite authorization check before serving backup archives and job logs. This flaw allows a network administrator who is not a Super Admin to download a complete backup of the entire network, potentially revealing sensitive content from all sites and the shared webroot. The breach results in a confidentiality compromise and could facilitate further compromise if the backup contains configuration files or credentials.

Affected Systems

JetBackup on WordPress multisite installations, versions 3.1.18.8 through 3.1.23.3, are affected. Any site that uses the plugin in this range is vulnerable.

Risk and Exploitability

The vulnerability is exploitable by individuals with network admin rights but not super admin rights, a common role in larger organisations. The CVSS score of 4.4 indicates moderate severity, and the EPSS score of < 1% suggests a low likelihood of exploitation, and it is not listed in the CISA KEV catalog. If an attacker can leverage the privileged network admin role, they can download a full backup of the entire network with minimal effort, which could expose sensitive data and compromise confidentiality.

Generated by OpenCVE AI on August 27, 2026 at 16:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade JetBackup to version 3.1.23.5 or newer
  • Restrict or remove backup download permissions for non‑Super‑Admin network administrators
  • Monitor administrative activity for attempted unauthorized backup downloads

Generated by OpenCVE AI on August 27, 2026 at 16:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 27 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Jetbackup
Jetbackup jetbackup
Wordpress
Wordpress wordpress
Vendors & Products Jetbackup
Jetbackup jetbackup
Wordpress
Wordpress wordpress

Thu, 27 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup archives and job logs, allowing an administrator of the network's main site who is not a Super Admin to download a full backup of the entire network, including every site's data and the shared webroot.
Title JetBackup 3.1.18.8 - 3.1.23.3 - Admin+ Multisite Network Backup Download
References

Subscriptions

Jetbackup Jetbackup
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-27T14:23:47.496Z

Reserved: 2026-08-10T14:10:21.471Z

Link: CVE-2026-19454

cve-icon Vulnrichment

Updated: 2026-08-27T14:15:17.791Z

cve-icon NVD

Status : Deferred

Published: 2026-08-27T06:16:57.207

Modified: 2026-08-28T18:43:25.883

Link: CVE-2026-19454

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T16:30:16Z

Weaknesses