← Zurück zur CVE-Suche

CVE-2026-76549

UpdraftPlus

Beschreibung

The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one of its backup management actions, which could allow attackers to make a logged in admin restore an existing backup, reverting the site-s database and files to an earlier state, via a crafted link.

CVSS 5.9EPSS 0.097%Risiko 0.6
Quelle öffnen
Veröffentlicht
2026-08-27 06:17:26
Betroffene Versionen
<1.26.7
Typ
Webanwendung
Zuletzt geändert
2026-08-27 17:20:17
Vektor
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:L