CVE-2026-41560: WordPress WXD Backup Lite plugin <= 1.0.2 - Broken Access Control vulnerability
Published Oct 6, 2026
·Updated
Unauthenticated Broken Access Control in WXD Backup Lite <= 1.0.2 versions.
Affected Software
1 affected component
WordPress WXD Backup Lite<=1.0.2
Event History
Oct 6, 2026
CVE Published
via MITRE·08:34 AM
Data Sourced
via MITRE·08:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated and requires no user interaction, so a remote attacker does not need a WordPress account to exploit it.
2
What impact is indicated by the severity vector?
The supplied vector indicates high confidentiality impact, with no integrity or availability impact indicated. Exploitation is rated low complexity and remotely reachable over the network.
3
Which plugin versions are affected?
WXD Backup Lite versions through 1.0.2 are identified as affected.