CVE-2026-39480: WordPress Backup Migration plugin <= 2.1.1 - Sensitive Data Exposure vulnerability
Published Jun 15, 2026
·Updated
Unauthenticated Sensitive Data Exposure in Backup Migration <= 2.1.1 versions.
Affected Software
1 affected component
WordPress Backup Migration plugin<=2.1.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Backup Migration pluginto a version that resolves this vulnerability.Fixed in 2.1.2
Event History
Jun 15, 2026
CVE Published
via MITRE·08:17 PM
Data Sourced
via MITRE·08:17 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-39480?
CVE-2026-39480 has a severity score of 7.5, classified as high.
2
How do I fix CVE-2026-39480?
To fix CVE-2026-39480, update the WordPress Backup Migration plugin to version 2.1.2 or later.
3
What does CVE-2026-39480 affect?
CVE-2026-39480 affects versions of the WordPress Backup Migration plugin up to and including 2.1.1.
4
What type of vulnerability is CVE-2026-39480?
CVE-2026-39480 is categorized as an unauthenticated sensitive data exposure vulnerability.
5
What are the potential risks of CVE-2026-39480?
The risks of CVE-2026-39480 include unauthorized access to sensitive data due to lack of authentication controls.