CVE-2026-6227: BackWPup <= 5.6.6 - Authenticated (Administrator+) Local File Inclusion via 'block_name' Parameter
The BackWPup plugin for WordPress is vulnerable to Local File Inclusion via the blockname parameter of the /wp-json/backwpup/v1/getblock REST endpoint in all versions up to, and including, 5.6.6 due to a non-recursive strreplace() sanitization of path traversal sequences. This makes it possible for authenticated attackers, with Administrator-level access and above, to include arbitrary PHP files on the server via crafted traversal sequences (e.g., ....//), which can be leveraged to read sensitive files such as wp-config.php or achieve remote code execution in certain configurations. Administrators have the ability to grant individual users permission to handle backups, which may then allow lower-level users to exploit this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Remove or reduce Administrator-level permissions that allow individual users to handle backups, so that lower-level users cannot exploit this Local File Inclusion in BackWPup (authenticated Administrator+).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6227?
CVE-2026-6227 is rated as high severity due to its potential for local file inclusion, which could lead to unauthorized access to sensitive files.
How do I fix CVE-2026-6227?
To fix CVE-2026-6227, update the BackWPup plugin to version 5.6.7 or later.
Who is affected by CVE-2026-6227?
All users of the BackWPup plugin for WordPress versions up to and including 5.6.6 are affected by CVE-2026-6227.
What type of vulnerability is CVE-2026-6227?
CVE-2026-6227 is a local file inclusion (LFI) vulnerability that allows attackers to include files on the server through the 'block_name' parameter.
What can attackers do with CVE-2026-6227?
With CVE-2026-6227, attackers can exploit the vulnerability to read sensitive files from the server, potentially gaining access to critical system information.