CVE-2026-86828: vulnerability in BackWPup
BackWPup < 5.7.7 - Admin+ Path Traversal to RCE via Restore PclZip Fallback
Published
0Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Track
exploitation probability
—
observed exploitation
nono source reports it
The BackWPup WordPress plugin before 5.7.7 does not properly restrict the destination path of files extracted during a backup restore when its fallback archive library is used, allowing high-privileged users to write files outside the intended restore directory, potentially leading to remote code execution.
Affected products
Unknown · BackWPupRelated CVEs — BackWPup
In the same product, most dangerous first.
CVE-2023-7164HIGHBackWPup < 4.0.4 - Unauthenticated Backup DownloadEPSS 2.3%CVE-2026-86815MEDIUMBackWPup 5.2.2 - 5.7.4 - BackWPup Jobs Checker+ Database Backup Exfiltration via Missing Authorization on Job REST RoutesEPSS 0.4%CVE-2026-86827—BackWPup 3.3 - 5.7.6 - Unauthenticated Backup Job Execution via wp-cron.phpEPSS —CVE-2026-86826—BackWPup < 5.7.7 - Unauthenticated Sensitive Data Disclosure via Restore Working Directory on NGINXEPSS —