CVE-2026-86815: BackWPup 5.2.2 - 5.7.4 - BackWPup Jobs Checker+ Database Backup Exfiltration via Missing Authorization on Job REST Routes
The BackWPup WordPress plugin before 5.7.5 does not properly restrict access to several of its REST API routes for job, backup-destination, and backup-execution management, allowing users holding a BackWPup WordPress plugin before 5.7.5-defined, administrator-assigned limited role to create and run backup jobs and exfiltrate a full database backup to an attacker-controlled destination.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
BackWPup (WordPress plugin)to a version that resolves this vulnerability.Fixed in 5.7.5 - Compensating control
Restrict access to BackWPup REST API endpoints related to job, backup-destination, and backup-execution management so that only fully authorized administrators can create/run jobs and manage backup destinations, mitigating the missing authorization on routes prior to 5.7.5.
Event History
Frequently Asked Questions
Which BackWPup installations are affected?
BackWPup versions before 5.7.5 are affected. Installations running 5.2.2 through 5.7.4 should be treated as vulnerable.
What level of access does an attacker need?
An attacker needs a BackWPup-defined limited role that has been assigned by a WordPress administrator. The issue does not describe unauthenticated exploitation.
What can a successful attacker do?
They can create and run backup jobs through insufficiently restricted REST API routes, then send a full database backup to an attacker-controlled destination.