PT-2026-82391 · WordPress · Jetbackup

·

CVE-2026-19454

·

Published

2026-08-27

·

Updated

2026-08-27

CVSS v3.1

4.4

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions JetBackup WordPress plugin versions prior to 3.1.23.5
Description Insufficient multisite authorization checks occur before serving backup archives and job logs. This allows an administrator of the network's main site, who lacks Super Admin privileges, to download a full backup of the entire network, including the shared webroot and data from every site.
Recommendations Update JetBackup WordPress plugin to version 3.1.23.5 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19454

Affected Products

Jetbackup