Get real-time updates on Telegram
Verified
CVE-2026-86827: BackWPup 3.3 to before 5.7.7
Affected technology
BackWPup · 3.3 to before 5.7.7
Vendor not specified by the source
Description’s affected range: before 5.7.7 does not verify that a request to its cron-triggered backup execution handler actually originates from WordPress's internal scheduled-event dispatch
Component: Not specified by the source
What an attacker can do
Unauthenticated attackers can force any existing backup job to run immediately, independent of its configured trigger type or schedule.
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-08 08:50:52.119177+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-08 08:49:39.219831+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-86827.html