WordPress security changelog
UNKNOWN CVE-2026-101148 Received

BackupSheep WordPress Backup Plugin: Arbitrary file deletion

The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, including the database with user password hashes, and to delete arbitrary files on the server, leading to sensitive data disclosure and site takeover. The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 has been closed on WordPress.org since July 2024 and no fixed version is available. Remove it from any site where it is installed. The authoritative export does not name the request parameter or handler beyond the affected feature described above.

CVE / CNA score Pending The CVE record has not published a CNA CVSS assessment.
NVD score Pending NVD has not published its own CVSS assessment.
Component
BackupSheep WordPress Backup Plugin
Plugin slug
backupsheep-wordpress-backup-plugin
Affected
<= 1.8
Safe version
See mitigation notes
Published
Oct 01, 2026
Weakness
Not assigned

This CVE was published Oct 01, 2026 and is one of 1 known issue for this plugin.

Update, patch or deactivate.

Remove this closed component. Reject empty integration keys, authenticate every backup operation and confine file deletion to authorized backup files; rotate secrets contained in exposed backups.

No confirmed safe version is listed. Consider a vendor-supported patch or temporarily restricting the affected functionality while you assess the risk.

Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.

Technical description

The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, including the database with user password hashes, and to delete arbitrary files on the server, leading to sensitive data disclosure and site takeover. The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 has been closed on WordPress.org since July 2024 and no fixed version is available. Remove it from any site where it is installed.

Primary and upstream sources