CYBER CODE RED

Get real-time updates on Telegram

Verified

CVE-2026-86828: BackWPup 0 to before 5.7.7

Affected technology

BackWPup · 0 to before 5.7.7
Vendor not specified by the source

Description’s affected range: before 5.7.7 does not properly restrict the destination path of files extracted during a backup restore when its fallback archive library is used

Component: Not specified by the source

What an attacker can do

The source says the BackWPup WordPress plugin before 5.7.7 does not properly restrict the destination path of files extracted during a backup restore when its fallback archive library is used, allowing high-privileged users to write files outside the intended restore directory, potentially leading to remote code execution.

Published

KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-86828.html