PT-2026-107845 · WordPress · Backwpup

·

CVE-2026-86828

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

6.6

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BackWPup WordPress plugin versions prior to 5.7.7
Description An issue exists when the fallback archive library is used during a backup restore process. The plugin fails to properly restrict the destination path of extracted files, which allows high-privileged users to write files outside the intended restore directory. This behavior could potentially lead to remote code execution.
Recommendations Update BackWPup WordPress plugin to version 5.7.7 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86828

Affected Products

Backwpup