CVE-2026-97197: WordPress WordPress Backup & Migration plugin <= 1.6.0 - Broken Access Control vulnerability
Published Sep 30, 2026
·Updated
Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions.
Affected Software
1 affected component
WordPress WordPress Backup & Migration<=1.6.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Backup & Migration pluginto a version that resolves this vulnerability.Fixed in 1.6.1
Event History
Sep 30, 2026
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
No authentication or prior privileges are required. The vector is network-accessible, and exploitation does not require user interaction.
2
What is the likely security impact?
The vulnerability has high confidentiality impact. The provided scoring indicates no integrity or availability impact.
3
Which plugin versions are affected?
WordPress Backup & Migration versions 1.6.0 and earlier are identified as affected.