PT-2026-60708 · Ploudapp+1 · Pcloud Backup+1

·

CVE-2026-14503

·

Published

2026-07-16

·

Updated

2026-07-17

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions pCloud WP Backup versions prior to 2.0.4
Description An issue exists in the wp2pcl ajax process request inner function that allows authenticated users with subscriber-level access or higher to force the generation of a full-site backup archive. This archive is stored in a publicly accessible tmp/ directory at a predictable URL, enabling unauthenticated visitors to access sensitive data. The exposed information includes the wp-config.php file containing database credentials, WordPress secret salts, and the entire PHP source tree.
Recommendations Update pCloud WP Backup to version 2.0.4 or later.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14503

Affected Products

Pcloud Backup
Pcloud-Wp-Backup