PT-2026-107845 · WordPress · Backwpup
CVSS v3.1
6.6
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BackWPup WordPress plugin versions prior to 5.7.7
Description
An issue exists when the fallback archive library is used during a backup restore process. The plugin fails to properly restrict the destination path of extracted files, which allows high-privileged users to write files outside the intended restore directory. This behavior could potentially lead to remote code execution.
Recommendations
Update BackWPup WordPress plugin to version 5.7.7 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Backwpup