← WordPress Vulnerabilities
WordPress security by component

BackWPup – WordPress Backup & Restore Plugin

BackWPup – WordPress Backup & Restore Plugin creates and restores WordPress backups of site files and databases using configurable storage destinations.

BackWPup – WordPress Backup & Restore Plugin (backwpup) is a WordPress plugin with 12 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 8.7.

Plugin slug: backwpup

CVE-2026-86815: BackWPup limited roles can exfiltrate database backups

BackWPup before 5.7.5 does not properly restrict several REST API routes used to manage jobs, backup destinations, and backup execution. A user holding a limited BackWPup role assigned by an administrator can create and run a backup job, direct the resulting full database backup to an attacker-controlled destination, and exfiltrate site data. The authoritative export does not name the individual routes, parameters, or permission callbacks.

PublishedSep 11, 2026
Known safe version5.7.5
Published vulnerabilities for backwpup
Safe version
Sep 11, 2026 CVE-2026-86815
BackWPup limited roles can exfiltrate database backups
BackWPup before 5.7.5 does not properly restrict several REST API routes used to manage jobs, backup destinations, and backup execution. A user holding a limited BackWPup role assigned by an administrator can create and run a backup job, direct the resulting full database backup to an attacker-controlled destination, and exfiltrate site data. The authoritative export does not name the individual routes, parameters, or permission callbacks.
5.7.5
CVE5.5
NVDPending
Jul 27, 2026 CVE-2026-65443
BackWPup public input permits cross-site scripting
BackWPup through 5.7.4 accepts attacker-controlled input through an unauthenticated request path and places it into a browser-executable output context without adequate neutralization. A victim who opens the crafted output can run script in the site's origin.
5.7.5
CVE7.1
NVDPending
Apr 14, 2026 CVE-2026-6227
BackWPup – WordPress Backup & Restore Plugin: Filesystem traversal
BackWPup – WordPress Backup & Restore Plugin is affected by filesystem traversal. Exploitation requires an authenticated administrator account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 5.6.6.
See mitigation notes
CVE7.2
NVDPending
Feb 19, 2026 CVE-2025-15041
BackWPup – WordPress Backup & Restore Plugin: Privilege escalation or authentication bypass
BackWPup – WordPress Backup & Restore Plugin is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated WordPress account. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE7.2
NVDPending
Aug 17, 2024 CVE-2023-5505
BackWPup: Filesystem traversal
BackWPup is affected by filesystem traversal. Exploitation requires an authenticated WordPress account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE6.8
NVD6.8
Apr 08, 2024 CVE-2023-7164
BackWPup: A security weakness
BackWPup is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending
Feb 26, 2024 CVE-2023-5775
BackWPup: A security weakness
BackWPup is affected by a security weakness. Exploitation requires an authenticated administrator account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE2.2
NVD2.7
Jan 11, 2024 CVE-2023-5504
BackWPup: Filesystem traversal
BackWPup is affected by filesystem traversal. Exploitation requires an authenticated WordPress account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.7
NVD8.7
Sep 28, 2017 CVE-2017-2551
Backwpup: A security weakness
Backwpup is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD7.5
Sep 26, 2013 CVE-2013-4626
Backwpup: Cross-site scripting
Backwpup is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD4.3
Oct 08, 2012 CVE-2011-5208
Backwpup: Filesystem traversal
Backwpup is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVEPending
NVD5.0
Oct 08, 2012 CVE-2011-4342
Backwpup: Code execution
Backwpup is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVEPending
NVD7.5