CVE WATCH / VULNERABILITY DETAIL
CVE-2026-101148
CRITICALCVSS 10NVD feed
Published 1 October 2026 · tracked since 1 October 2026
Description
The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, including the database with user password hashes, and to dele
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-97661 HIGH 7.2
- CVE-2026-92244 HIGH 7.2
- CVE-2026-95687 HIGH 8.8
- CVE-2026-96268 MEDIUM 6.4
- CVE-2026-96573 HIGH 7.2
- CVE-2026-96813 HIGH 7.2
- CVE-2026-15983 HIGH 8.1
- CVE-2026-85235 HIGH 7.2
- CVE-2026-89424 MEDIUM 6.4
- CVE-2026-90992 MEDIUM 6.4