CVE-2026-41561: WordPress Museder RestoreOne plugin <= 2.7.276 - Sensitive Data Exposure vulnerability
Published Oct 6, 2026
·Updated
Unauthenticated Sensitive Data Exposure in Museder RestoreOne <= 2.7.276 versions.
Affected Software
1 affected component
Museder RestoreOne<=2.7.276
Event History
Oct 6, 2026
CVE Published
via MITRE·08:34 AM
Data Sourced
via MITRE·08:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require an account or user interaction?
No. The vulnerability is rated with no privileges required and no user interaction required, so an unauthenticated attacker can exploit it without a WordPress account.
2
What is the expected security impact?
The reported impact is high confidentiality impact, meaning sensitive information may be exposed. No integrity or availability impact is indicated.
3
Does an attacker need local access to target the affected plugin?
No. The attack vector is network-based, indicating the issue can be targeted remotely over a network connection.