Impact
The BackWPup plugin for WordPress before version 5.7.7 fails to verify that a request sent to its cron‑triggered backup handler originates from WordPress’s internal scheduled‑event system. As a result, any attacker who can reach the wp‑cron.php endpoint can force any existing backup job to run immediately, regardless of its configured trigger type or schedule. This bypass of internal authentication allows unauthenticated users to trigger privileged backup operations, potentially impacting confidentiality, integrity, or availability of backups and site data.
Affected Systems
WordPress sites using the BackWPup plugin from version 3.3 through 5.7.6 are affected. The vulnerability is present in all builds within this range, irrespective of site configuration or other plugins.
Risk and Exploitability
The vulnerability can be exploited remotely via a simple HTTP request to wp‑cron.php without requiring authentication, making it an unauthenticated attack vector. The exploit presents a high risk: it allows arbitrary, immediate initiation of backup jobs which can lead to data leakage, unintended modification of backup settings, or resource exhaustion. No EPSS score is available and the issue is not listed in the CISA KEV catalog. Because the attack only needs a web request, the likelihood of exploitation is high in exposed WordPress installations.
OpenCVE Enrichment