PT-2026-48532 · WordPress+1 · Updraftplus+1

CVE-2026-10795

·

Published

2026-06-10

·

Updated

2026-09-08

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UpdraftPlus: WP Backup & Migration Plugin versions prior to 1.26.5
Description An authentication bypass exists in the UpdraftPlus Remote Communications V2::wp loaded() function due to insufficient validation of the remote communications message format. This flaw allows signature verification to be bypassed, causing unchecked decryption return values to collapse into a predictable all-zero encryption key. Consequently, unauthenticated attackers can forge arbitrary RPC (Remote Procedure Call) commands and execute them with administrator privileges, such as uploading and activating malicious plugins, which leads to remote code execution. This issue specifically affects sites connected to UpdraftCentral. Approximately 3 million devices worldwide are potentially affected, and there are reports of this issue being exploited in the wild.
Recommendations Update UpdraftPlus: WP Backup & Migration Plugin to version 1.26.5 or newer for the free version. Update UpdraftPlus: WP Backup & Migration Plugin to version 2.26.5 or newer for the premium version. Update UpdraftCentral to version 0.8.32 or later.

Fix

DoS

RCE

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10795

Affected Products

Updraftcentral
Updraftplus