Description
The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.8, UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 2.26.8.26 does not have any capability check in a routine that outputs its stored remote storage settings into admin pages when the site is left in a particular post-migration state, allowing any authenticated user, such as a subscriber, to retrieve the credentials of the configured backup destinations, such as passwords and secret keys.
Published: 2026-09-27
Score: n/a
EPSS: n/a
KEV: No
Impact: Credential Disclosure
Action: Patch
AI Analysis

Impact

The vulnerability lies in a missing capability check in UpdraftPlus: WP Backup & Migration Plugin. When a site is left in a specific post‑migration state, any authenticated user—such as a standard subscriber—can access an admin page that outputs the stored remote storage configuration, revealing passwords and secret keys used for backup destinations. This directly exposes sensitive credentials and can lead to further compromise of the backup services and the underlying file system.

Affected Systems

Vendors: UpdraftPlus, plugin versions prior to 1.26.8, and prior to 2.26.8.26 are affected. WordPress sites that have installed these vulnerable plugin releases are at risk.

Risk and Exploitability

The vulnerability can be leveraged by any authenticated user once the migration state issue has been triggered. Because the attacker only needs valid WordPress credentials, the attack vector is considered local with authenticated access. Exploitation does not require elevated privileges, making it readily achievable for regular plugin users. While the EPSS data is not available and the vulnerability is not in the CISA KEV catalog, the potential impact on confidentiality is high, as exposed credentials may grant access to cloud storage or backup services controlled by the site owner.

Generated by OpenCVE AI on September 27, 2026 at 07:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest UpdraftPlus plugin version—1.26.8 or later for the 1.x line, or 2.26.8.26 or newer for the 2.x line—to apply the vendor‑issued fix.
  • Restrict access to the remote storage configuration pages to users with administrator or editor capabilities, and remove any leftover migration‑related triggers that leave the site in the vulnerable state.
  • Verify that the plugin’s settings no longer display stored credentials by logging in and reviewing the backup configuration pages; if credentials still appear, clear them and re‑configure securely.
  • Monitor site logs for suspicious attempts to access backup settings and enforce strict role management on the WordPress installation.

Generated by OpenCVE AI on September 27, 2026 at 07:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Sun, 27 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.8, UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 2.26.8.26 does not have any capability check in a routine that outputs its stored remote storage settings into admin pages when the site is left in a particular post-migration state, allowing any authenticated user, such as a subscriber, to retrieve the credentials of the configured backup destinations, such as passwords and secret keys.
Title UpdraftPlus 1.23.8 - 1.26.7 - Subscriber+ Remote Storage Credential Disclosure via Migration Notice
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-27T06:00:19.369Z

Reserved: 2026-08-31T08:21:45.873Z

Link: CVE-2026-82841

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-27T06:17:03.433

Modified: 2026-09-27T06:17:03.433

Link: CVE-2026-82841

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T07:30:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control