CVE-2026-86828: Unknown Backwpup
Medium severity, CVSS 6.6. EPSS: 0.4% chance of exploitation in the next 30 days.
The BackWPup WordPress plugin before 5.7.7 does not properly restrict the destination path of files extracted during a backup restore when its fallback archive library is used, allowing high-privileged users to write files outside the intended restore directory, potentially leading to remote code execution.
Affected products
- Unknown Backwpup: before 5.7.7 (fixed in 5.7.7)
Published 2026-10-08. Last modified 2026-10-08.