CVE-2026-76549

Summary

The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one of its backup management actions, which could allow attackers to make a logged in admin restore an existing backup, reverting the site's database and files to an earlier state, via a crafted link.

Affected Software

VendorProductVersion RangeStatus
UnknownUpdraftPlus: WP Backup & Migration Plugin0 < 1.26.7affected

Weaknesses

  • CWE-352 Cross-Site Request Forgery (CSRF)

References