CVE-2026-76549
N/A
N/A
Summary
The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one of its backup management actions, which could allow attackers to make a logged in admin restore an existing backup, reverting the site's database and files to an earlier state, via a crafted link.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | UpdraftPlus: WP Backup & Migration Plugin | 0 < 1.26.7 | affected |
Weaknesses
- CWE-352 Cross-Site Request Forgery (CSRF)
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.