CVE-2026-19453: JetBackup 3.1.7.9 - 3.1.23.3 - Subscriber+ Privilege Escalation via Restore Admin User Selection
The JetBackup WordPress plugin before 3.1.23.5 does not verify the role or capabilities of the account it preserves across a restore or migration before granting it administrator privileges, allowing a subscriber-level user to gain administrator access after the site owner restores or migrates the site.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A subscriber-level WordPress user can exploit it. Exploitation occurs when the site owner performs a site restore or migration that preserves the attacker’s account.
Is a restore or migration required for exploitation?
Yes. The vulnerable behavior is triggered after the site owner restores or migrates the site and the plugin preserves an account without validating its role or capabilities.
Which versions are affected and what version fixes the issue?
JetBackup versions before 3.1.23.5 are affected; the reported affected range includes 3.1.7.9 through 3.1.23.3. Updating to 3.1.23.5 or later addresses the issue.