Description
The BackWPup WordPress plugin before 5.7.7 does not verify that a request to its cron-triggered backup execution handler actually originates from WordPress's internal scheduled-event dispatch, allowing unauthenticated attackers to force any existing backup job to run immediately, independent of its configured trigger type or schedule.
Published: 2026-10-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthorized execution of backup jobs
Action: Apply Patch
AI Analysis

Impact

The BackWPup plugin for WordPress before version 5.7.7 fails to verify that a request sent to its cron‑triggered backup handler originates from WordPress’s internal scheduled‑event system. As a result, any attacker who can reach the wp‑cron.php endpoint can force any existing backup job to run immediately, regardless of its configured trigger type or schedule. This bypass of internal authentication allows unauthenticated users to trigger privileged backup operations, potentially impacting confidentiality, integrity, or availability of backups and site data.

Affected Systems

WordPress sites using the BackWPup plugin from version 3.3 through 5.7.6 are affected. The vulnerability is present in all builds within this range, irrespective of site configuration or other plugins.

Risk and Exploitability

The vulnerability can be exploited remotely via a simple HTTP request to wp‑cron.php without requiring authentication, making it an unauthenticated attack vector. The exploit presents a high risk: it allows arbitrary, immediate initiation of backup jobs which can lead to data leakage, unintended modification of backup settings, or resource exhaustion. No EPSS score is available and the issue is not listed in the CISA KEV catalog. Because the attack only needs a web request, the likelihood of exploitation is high in exposed WordPress installations.

Generated by OpenCVE AI on October 8, 2026 at 07:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade BackWPup to version 5.7.7 or later
  • Restrict access to the wp‑cron.php endpoint at the web server level (e.g., using .htaccess or firewall rules) so that only trusted IPs or the WordPress process can invoke it
  • Disable or secure external calls to the cron system by using a non‑cached cron implementation or by configuring the site to run WP‑cron jobs internally

Generated by OpenCVE AI on October 8, 2026 at 07:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Thu, 08 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The BackWPup WordPress plugin before 5.7.7 does not verify that a request to its cron-triggered backup execution handler actually originates from WordPress's internal scheduled-event dispatch, allowing unauthenticated attackers to force any existing backup job to run immediately, independent of its configured trigger type or schedule.
Title BackWPup 3.3 - 5.7.6 - Unauthenticated Backup Job Execution via wp-cron.php
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-08T06:00:08.008Z

Reserved: 2026-09-08T14:25:04.427Z

Link: CVE-2026-86827

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T06:16:44.987

Modified: 2026-10-08T06:16:44.987

Link: CVE-2026-86827

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T07:45:17Z

Weaknesses