WordPress Plugin Vulnerabilities

BackupSheep <= 1.8 - Unauthenticated Arbitrary File Deletion and Backup Exfiltration via Empty Integration Key

Description

The plugin does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, including the database with user password hashes, and to delete arbitrary files on the server, leading to sensitive data disclosure and site takeover.

The plugin has been closed on WordPress.org since July 2024 and no fixed version is available. Remove it from any site where it is installed.

Proof of Concept

Affects Plugins

No known fix

References

Classification

Type
FILE DELETION
CWE

Miscellaneous

Original Researcher
Enrico Marcolini, Claudio Marchesini, Dottor Marc
Submitter
Enrico Marcolini, Claudio Marchesini, Dottor Marc
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-29 (about 2 days ago)
Added
2026-09-29 (about 1 day ago)
Last Updated
2026-09-29 (about 1 day ago)

Other