CVE-2026-41562: WordPress Norvis Backup plugin <= 1.1.0 - Sensitive Data Exposure vulnerability
Unauthenticated Sensitive Data Exposure in Norvis Backup <= 1.1.0 versions.
Unauthenticated Sensitive Data Exposure in Norvis Backup <= 1.1.0 versions.
The issue is unauthenticated, so an attacker does not need a WordPress account or prior access to the site. The network attack vector and low attack complexity indicate it can be targeted remotely without special conditions stated in the available data.
The vulnerability exposes sensitive data. The supplied CVSS vector indicates high confidentiality impact, with no integrity or availability impact identified.
Norvis Backup versions up to and including 1.1.0 are affected. The available data does not state whether any particular plugin configuration is required.
The issue is rated high severity with a CVSS score of 7.5. Because exploitation requires no authentication or user interaction, affected internet-accessible WordPress sites should be prioritized for remediation.