PT-2026-48532 · WordPress+1 · Updraftplus+1
CVE-2026-10795
·
Published
2026-06-10
·
Updated
2026-09-08
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
UpdraftPlus: WP Backup & Migration Plugin versions prior to 1.26.5
Description
An authentication bypass exists in the
UpdraftPlus Remote Communications V2::wp loaded() function due to insufficient validation of the remote communications message format. This flaw allows signature verification to be bypassed, causing unchecked decryption return values to collapse into a predictable all-zero encryption key. Consequently, unauthenticated attackers can forge arbitrary RPC (Remote Procedure Call) commands and execute them with administrator privileges, such as uploading and activating malicious plugins, which leads to remote code execution. This issue specifically affects sites connected to UpdraftCentral. Approximately 3 million devices worldwide are potentially affected, and there are reports of this issue being exploited in the wild.Recommendations
Update UpdraftPlus: WP Backup & Migration Plugin to version 1.26.5 or newer for the free version.
Update UpdraftPlus: WP Backup & Migration Plugin to version 2.26.5 or newer for the premium version.
Update UpdraftCentral to version 0.8.32 or later.
Fix
DoS
RCE
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Updraftcentral
Updraftplus