CVE-2026-76549: UpdraftPlus < 1.26.7 - Backup Restoration via CSRF
The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one of its backup management actions, which could allow attackers to make a logged in admin restore an existing backup, reverting the site's database and files to an earlier state, via a crafted link.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
WordPress sites using UpdraftPlus versions before 1.26.7 are exposed if a logged-in administrator can be induced to visit a crafted link.
What does an attacker need to exploit it?
The attacker needs to cause a logged-in WordPress administrator to follow a crafted link. The vulnerable backup-management action can then restore an existing backup without CSRF checks.
What is the likely impact of successful exploitation?
A successful attack can revert the site's database and files to the state contained in an existing backup. This may undo content, configuration, or other changes made after that backup was created.
How can I determine whether my site is affected?
Check the installed UpdraftPlus version. Versions earlier than 1.26.7 are affected.