CVE-2026-82841

Summary

The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.8, UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 2.26.8.26 does not have any capability check in a routine that outputs its stored remote storage settings into admin pages when the site is left in a particular post-migration state, allowing any authenticated user, such as a subscriber, to retrieve the credentials of the configured backup destinations, such as passwords and secret keys.

Affected Software

VendorProductVersion RangeStatus
UnknownUpdraftPlus: WP Backup & Migration Plugin1.23.8 < 1.26.8affected
UnknownUpdraftPlus: WP Backup & Migration Plugin2.23.8 < 2.26.8.26affected

Weaknesses

  • CWE-200 Information Exposure

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References