CVE-2026-86827: vulnerability in BackWPup
BackWPup 3.3 - 5.7.6 - Unauthenticated Backup Job Execution via wp-cron.php
Published
0Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Track
exploitation probability
—
observed exploitation
nono source reports it
The BackWPup WordPress plugin before 5.7.7 does not verify that a request to its cron-triggered backup execution handler actually originates from WordPress's internal scheduled-event dispatch, allowing unauthenticated attackers to force any existing backup job to run immediately, independent of its configured trigger type or schedule.
Affected products
Unknown · BackWPupRelated CVEs — BackWPup
In the same product, most dangerous first.
CVE-2023-7164HIGHBackWPup < 4.0.4 - Unauthenticated Backup DownloadEPSS 2.3%CVE-2026-86815MEDIUMBackWPup 5.2.2 - 5.7.4 - BackWPup Jobs Checker+ Database Backup Exfiltration via Missing Authorization on Job REST RoutesEPSS 0.4%CVE-2026-86828—BackWPup < 5.7.7 - Admin+ Path Traversal to RCE via Restore PclZip FallbackEPSS —CVE-2026-86826—BackWPup < 5.7.7 - Unauthenticated Sensitive Data Disclosure via Restore Working Directory on NGINXEPSS —