CVE-2026-65443: WordPress BackWPup plugin <= 5.7.4 - Cross Site Scripting (XSS) vulnerability
Published Jul 27, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.
Affected Software
1 affected component
BackWPup BackWPup<=5.7.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress BackWPup pluginto a version that resolves this vulnerability.Fixed in 5.7.5
Event History
Jul 27, 2026
CVE Published
via MITRE·10:44 PM
Data Sourced
via MITRE·10:44 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-65443?
The severity of CVE-2026-65443 is rated high with a score of 7.1.
2
How do I fix CVE-2026-65443?
To fix CVE-2026-65443, update the BackWPup plugin to version 5.7.5 or later.
3
What type of vulnerability is CVE-2026-65443?
CVE-2026-65443 is categorized as a Cross Site Scripting (XSS) vulnerability.
4
Who is affected by CVE-2026-65443?
CVE-2026-65443 affects users of the BackWPup plugin versions 5.7.4 and earlier.
5
What impact does CVE-2026-65443 have on my website?
CVE-2026-65443 can allow unauthenticated attackers to execute malicious scripts on your website.