Get real-time updates on Telegram
Verified
CVE-2026-86828: BackWPup 0 to before 5.7.7
Affected technology
BackWPup · 0 to before 5.7.7
Vendor not specified by the source
Description’s affected range: before 5.7.7 does not properly restrict the destination path of files extracted during a backup restore when its fallback archive library is used
Component: Not specified by the source
What an attacker can do
The source says the BackWPup WordPress plugin before 5.7.7 does not properly restrict the destination path of files extracted during a backup restore when its fallback archive library is used, allowing high-privileged users to write files outside the intended restore directory, potentially leading to remote code execution.
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-08 08:50:52.119177+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-08 08:49:39.219831+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-86828.html