CVE WATCH / VULNERABILITY DETAIL

CVE-2026-86828

MEDIUMCVSS 6.6NVD feed

Published 8 October 2026 · tracked since 8 October 2026

Description

The BackWPup WordPress plugin before 5.7.7 does not properly restrict the destination path of files extracted during a backup restore when its fallback archive library is used, allowing high-privileged users to write files outside the intended restore directory, potentially leading to remote code e

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-86828 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-86828

MEDIUMCVSS 6.6NVD feed

Published 8 October 2026 · tracked since 8 October 2026

Description

The BackWPup WordPress plugin before 5.7.7 does not properly restrict the destination path of files extracted during a backup restore when its fallback archive library is used, allowing high-privileged users to write files outside the intended restore directory, potentially leading to remote code e

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]