CVE-2026-101148: BackupSheep <= 1.8 - Unauthenticated Arbitrary File Deletion and Backup Exfiltration via Empty Integration Key
The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, including the database with user password hashes, and to delete arbitrary files on the server, leading to sensitive data disclosure and site takeover.
The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 has been closed on WordPress.org since July 2024 and no fixed version is available. Remove it from any site where it is installed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
BackupSheep WordPress Backup Pluginfrom your environment.Remove BackupSheep from any site where it is installed.
Event History
Frequently Asked Questions
Which installations are exposed to unauthenticated exploitation?
BackupSheep installations through version 1.8 are affected when the integration key is unset or blank, because the plugin treats that state as valid. An attacker does not need an account or other authentication.
What could an attacker obtain or do after exploiting this issue?
An attacker can create and download full site backups, including the database and user password hashes. They can also delete arbitrary files on the server, which can lead to sensitive-data disclosure and site takeover.
Is a patch available, and what should be done if the plugin is installed?
No fixed version is available. The plugin has been closed on WordPress.org since July 2024; remove it from every site where it is installed.