Description
The BackWPup WordPress plugin before 5.7.7 does not properly restrict web access to the working directory it uses during backup restores, allowing unauthenticated attackers, on webservers that do not honour .htaccess rules such as NGINX, to download the full backup archive (database dump and site files, including credentials and secret keys) left behind by an interrupted restore.
Published: 2026-10-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Sensitive data exposure via backup archive download
Action: Apply Patch
AI Analysis

Impact

The BackWPup WordPress plugin before version 5.7.7 fails to restrict web access to its working directory during backup restores. An unauthenticated attacker who can reach the site via a web server that does not honor .htaccess rules, such as NGINX, can download the full backup archive left behind after an interrupted restore. The archive contains the database dump and site files, including credentials and secret keys, resulting in a complete exposure of sensitive data.

Affected Systems

BackWPup plugin for WordPress installations running any version earlier than 5.7.7 on web servers like NGINX that ignore .htaccess. Any site using the backup/restore feature therefore is affected.

Risk and Exploitability

The vulnerability allows unauthenticated download of backup artifacts, leading to confidentiality loss. The attack does not require prior authentication and only needs a web request to the working directory. The EPSS score is not available and the vulnerability is not listed in CISA KEV. No CVSS score is provided, but the impact is significant due to complete credential exposure. primary attack vector is web-based, and the conditions are a running BackWPup plugin in a version older than 5.7.7 on a server that allows unrestricted access to the working directory.

Generated by OpenCVE AI on October 8, 2026 at 07:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade BackWPup to version 5.7.7 or later.
  • Configure the web server to deny access to the BackWPup working directory; for example, add an NGINX location block that returns a 403 or 404 for that path.
  • Delete any leftover backup archives from previous interrupted restores to remove exposed data.

Generated by OpenCVE AI on October 8, 2026 at 07:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Thu, 08 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The BackWPup WordPress plugin before 5.7.7 does not properly restrict web access to the working directory it uses during backup restores, allowing unauthenticated attackers, on webservers that do not honour .htaccess rules such as NGINX, to download the full backup archive (database dump and site files, including credentials and secret keys) left behind by an interrupted restore.
Title BackWPup < 5.7.7 - Unauthenticated Sensitive Data Disclosure via Restore Working Directory on NGINX
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-08T06:00:07.831Z

Reserved: 2026-09-08T14:24:10.830Z

Link: CVE-2026-86826

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T06:16:44.617

Modified: 2026-10-08T06:16:44.617

Link: CVE-2026-86826

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T07:45:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor