Sceawere
Vulnerability Detail
CVE-2026-86827UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
BackWPup Unauthenticated Arbitrary Job Execution
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- BackWPup
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The BackWPup WordPress plugin before 5.7.7 does not verify that a request to its cron-triggered backup execution handler actually originates from WordPress's internal scheduled-event dispatch, allowing unauthenticated attackers to force any existing backup job to run immediately, independent of its configured trigger type or schedule.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-08T06:16:44.987Z",
"pubdate": "2026-10-08T06:16:44.987Z",
"executiveSummary": "The BackWPup WordPress plugin prior to version 5.7.7 contains a critical security vulnerability involving an improper verification of the source for its cron-triggered backup execution handler.\nThis vulnerability is classified as an improper access control or authentication bypass issue, allowing unauthenticated remote attackers to trigger pre-configured backup jobs.\nBy bypassing the internal WordPress scheduled-event dispatch mechanism, an attacker can force the execution of any defined backup task on demand.\nThe primary risk implications include potential server resource exhaustion (Denial of Service) through continuous backup cycles, the potential exposure of sensitive backup data if stored in accessible locations, and the manipulation of system operations.\nExploitation requires no authentication and relies on the attacker's ability to trigger the vulnerable execution endpoint via network requests.\nThe affected product is BackWPup versions before 5.7.7. Immediate patching is required to ensure that the backup execution handler correctly validates the origin of incoming requests.",
"technicalDetails": "The vulnerability resides within the backup execution handler of the BackWPup plugin. The plugin utilizes a cron-triggered mechanism to automate backup processes; however, it fails to implement sufficient verification to ensure that the request to initiate a backup job originates from the legitimate WordPress internal scheduled-event system.\nRoot Cause: The root cause is a failure in access control validation. The script responsible for processing backup jobs does not verify the authenticity of the trigger signal. Consequently, the endpoint exposed by this handler is accessible to any remote user who can construct a valid request directed at the plugin's execution controller.\nAttack Flow: An attacker identifies the specific URI or endpoint associated with the BackWPup backup execution trigger. Since the component does not authenticate the request source, the attacker transmits a crafted HTTP GET or POST request directly to the server. The application processes the request, interprets it as a legitimate cron execution signal, and proceeds to invoke the backup job logic.\nExploitation Method: An unauthenticated attacker sends a request to the plugin's handler, effectively bypassing the intended schedule logic. Because the plugin accepts these requests without checking for a nonces or internal WordPress privileges, the attacker can force the plugin to execute high-resource tasks, such as dumping database contents or archiving site files, regardless of the user-defined frequency or timing.\nAffected Versions: All versions of BackWPup prior to 5.7.7 are confirmed vulnerable. The flaw is inherent in the plugin's request handling logic for automated tasks.\nAuthentication and Privileges: No authentication or administrative privileges are required to exploit this flaw, as the vulnerable endpoint is exposed to the public network. The attack vector is purely remote.\nPost-Exploitation Impact: Beyond the immediate forced execution of backups, an attacker may leverage this vulnerability to exhaust server CPU and I/O resources, potentially leading to a self-inflicted Denial of Service (DoS) condition. Furthermore, if the backup jobs are configured to store archives in publicly accessible web directories or cloud buckets, the forced execution provides the attacker with a mechanism to verify the creation and location of these sensitive files for potential exfiltration."
}