Description
Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore &amp; Migration <= 2.4.2 versions.
Published: 2026-09-10
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Sensitive Data Exposure
Action: Patch Upgrade
AI Analysis

Impact

The vulnerability is a failure of proper access controls that permits any unauthenticated user to retrieve sensitive data stored by the WordPress ZHBackup – Backup, Restore & Migration Plugin. The flaw arises from insufficient verification of user credentials before disclosing backup archives or configuration information, which can lead to the disclosure of confidential data such as passwords, encryption keys, and personal user information. This weakness is classified as CWE‑201: Sensitive Information Exposure, and the potential impact is the loss of confidentiality of data that was intended to be protected or only accessible by authorized administrators.

Affected Systems

WordPress sites that use Zain Hassan’s ZHBackup – Backup, Restore & Migration Plugin version 2.4.2 or earlier are impacted. The plugin is the sole product identified by the CNA and is affected across all environments where it is deployed without upgrade.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.5, indicating a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw can be exploited by accessing the plugin’s backup endpoints without authentication, an attacker could obtain sensitive data remotely. The lack of an EPSS value means that the current quantified likelihood of exploitation is unknown, but the high CVSS score and open web access increase the practical risk for exposed installations.

Generated by OpenCVE AI on September 10, 2026 at 15:38 UTC.

Remediation

Vendor Solution

Update the WordPress ZHBackup – Backup, Restore &amp; Migration Plugin to the latest available version (at least 2.4.3).


OpenCVE Recommended Actions

  • Update the WordPress ZHBackup – Backup, Restore & Migration Plugin to version 2.4.3 or later.
  • Restrict or disable backup functionality on the site until the plugin is patched, ensuring that no sensitive backup data can be accessed by unauthorized users.
  • Delete or secure any backup archives that were created with the vulnerable plugin version to eliminate residual exposed data.

Generated by OpenCVE AI on September 10, 2026 at 15:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore &amp; Migration <= 2.4.2 versions.
Title WordPress ZHBackup – Backup, Restore & Migration plugin <= 2.4.2 - Sensitive Data Exposure vulnerability
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-10T14:23:49.922Z

Reserved: 2026-08-27T12:24:38.075Z

Link: CVE-2026-81804

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-10T15:17:46.827

Modified: 2026-09-10T15:43:28.913

Link: CVE-2026-81804

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T15:45:05Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data