← WordPress Vulnerabilities
WordPress security by component

JetBackup – WP Backup, Migrate & Restore

JetBackup – WP Backup, Migrate & Restore backs up, restores, and migrates WordPress websites and their associated data.

JetBackup – WP Backup, Migrate & Restore (jetbackup) is a WordPress plugin with 6 published CVE records in this archive. The latest tracked vulnerability was published Sep 02, 2026; the highest published CVSS base score is 8.8.

Plugin slug: jetbackup

CVE-2026-19453: JetBackup restores can elevate a Subscriber to Administrator

JetBackup 3.1.7.9 through 3.1.23.4 does not verify the role or capabilities of an account preserved during restore or migration before granting it Administrator privileges. A Subscriber-level account can become an Administrator after the site owner performs the affected restore or migration.

PublishedSep 02, 2026
Known safe version3.1.23.5
Published vulnerabilities for jetbackup
Safe version
Sep 02, 2026 CVE-2026-19453
JetBackup restores can elevate a Subscriber to Administrator
JetBackup 3.1.7.9 through 3.1.23.4 does not verify the role or capabilities of an account preserved during restore or migration before granting it Administrator privileges. A Subscriber-level account can become an Administrator after the site owner performs the affected restore or migration.
3.1.23.5
CVE7.1
NVDPending
Aug 27, 2026 CVE-2026-19454
JetBackup main-site administrators can download full multisite backups
JetBackup 3.1.18.8 through versions before 3.1.23.5 serves backup archives and job logs before enforcing its multisite authorization boundary. An administrator of the network's main site who is not a Super Admin can download a full network backup, including every site's data and the shared webroot.
3.1.23.5
CVE4.4
NVDPending
Feb 27, 2024 CVE-2023-7165
JetBackup: A security weakness
JetBackup is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending
Mar 07, 2023 CVE-2020-36669
JetBackup – WP Backup, Migrate & Restore: Cross-site request forgery
JetBackup – WP Backup, Migrate & Restore is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE8.8
NVD8.8
Mar 07, 2023 CVE-2020-36668
JetBackup – WP Backup, Migrate & Restore: Sensitive information exposure
JetBackup – WP Backup, Migrate & Restore is affected by sensitive information exposure. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE4.3
NVD4.3
Mar 07, 2023 CVE-2020-36667
JetBackup – WP Backup, Migrate & Restore: A security weakness
JetBackup – WP Backup, Migrate & Restore is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD5.4