CYBER CODE RED

Get real-time updates on Telegram

Verified

CVE-2026-86827: BackWPup 3.3 to before 5.7.7

Affected technology

BackWPup · 3.3 to before 5.7.7
Vendor not specified by the source

Description’s affected range: before 5.7.7 does not verify that a request to its cron-triggered backup execution handler actually originates from WordPress's internal scheduled-event dispatch

Component: Not specified by the source

What an attacker can do

Unauthenticated attackers can force any existing backup job to run immediately, independent of its configured trigger type or schedule.

Published

KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-86827.html