Sceawere
Vulnerability Detail
CVE-2026-86828UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
BackWPup Arbitrary File Write RCE
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.6
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- BackWPup
- Attack Type
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
The BackWPup WordPress plugin before 5.7.7 does not properly restrict the destination path of files extracted during a backup restore when its fallback archive library is used, allowing high-privileged users to write files outside the intended restore directory, potentially leading to remote code execution.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.6",
"pubDate": "2026-10-08T06:16:45.287Z",
"pubdate": "2026-10-08T06:16:45.287Z",
"executiveSummary": "The BackWPup WordPress plugin prior to version 5.7.7 contains a critical path traversal vulnerability within its backup restoration mechanism.\nThe vulnerability stems from insufficient input validation when processing archive files using the plugin's fallback archive library, which fails to restrict the destination path of extracted files.\nSuccessful exploitation allows an authenticated user with high-level privileges to perform arbitrary file writes outside the intended backup directory.\nBy writing malicious files, such as PHP scripts, to accessible web server locations, an attacker can achieve remote code execution (RCE) on the underlying server.\nThis vulnerability poses a severe security risk, as it effectively grants a privileged attacker complete control over the application environment.\nThe attack requires prior authentication with high privileges, limiting the initial vector but significantly magnifying the potential impact of a compromised administrative account.",
"technicalDetails": "The vulnerability exists within the restore functionality of the BackWPup plugin, specifically when the system utilizes the fallback archive library for file extraction. The root cause is a failure to properly sanitize or validate the file paths contained within the backup archive before writing those files to the filesystem.\nWhen a backup restoration is initiated, the plugin processes the archive content. Because the fallback library lacks restrictive path checks, it is susceptible to path traversal techniques, often involving the use of '..' (parent directory) sequences within the file entries of the archive.\nAn attacker can craft a malicious backup archive containing files with path-traversal names. When this archive is restored, the plugin, failing to constrain the destination to the intended restore directory, writes the files to an arbitrary location specified by the attacker-controlled path.\nThe attack flow follows these steps: 1) An attacker with high-level privileges accesses the backup restoration feature of the BackWPup plugin. 2) The attacker uploads or selects a maliciously crafted backup archive designed to exploit the path traversal vulnerability. 3) The plugin processes the archive using the vulnerable fallback library. 4) The library fails to perform proper path canonicalization or validation, allowing the extracted files to be written outside the secure boundary. 5) By placing a PHP payload into a publicly accessible directory or a directory that is subsequently parsed by the web server (such as the web root or a plugin folder), the attacker triggers the payload. 6) Execution of the payload results in arbitrary code execution under the context of the web server user.\nThis vulnerability affects all versions of the BackWPup plugin prior to 5.7.7. The exploitation requires high-privileged user access, meaning an attacker must first obtain or possess administrative credentials or otherwise escalate privileges to interact with the backup restoration functionality. Post-exploitation, the attacker can leverage the RCE to install backdoors, exfiltrate sensitive data, or perform further lateral movement within the hosting environment."
}