← WordPress Vulnerabilities
WordPress security by component

BackupSheep WordPress Backup Plugin

BackupSheep WordPress Backup Plugin (backupsheep-wordpress-backup-plugin) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Oct 01, 2026; an upstream CVSS base score is still pending.

Plugin slug: backupsheep-wordpress-backup-plugin

CVE-2026-101148: BackupSheep WordPress Backup Plugin: Arbitrary file deletion

The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, including the database with user password hashes, and to delete arbitrary files on the server, leading to sensitive data disclosure and site takeover. The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 has been closed on WordPress.org since July 2024 and no fixed version is available. Remove it from any site where it is installed. The authoritative export does not name the request parameter or handler beyond the affected feature described above.

PublishedOct 01, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for backupsheep-wordpress-backup-plugin
Safe version
Oct 01, 2026 CVE-2026-101148
BackupSheep WordPress Backup Plugin: Arbitrary file deletion
The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, including the database with user password hashes, and to delete arbitrary files on the server, leading to sensitive data disclosure and site takeover. The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 has been closed on WordPress.org since July 2024 and no fixed version is available. Remove it from any site where it is installed. The authoritative export does not name the request parameter or handler beyond the affected feature described above.
See mitigation notes
CVEPending
NVDPending