WordPress Plugin Vulnerabilities

BackWPup 3.3 - 5.7.6 - Unauthenticated Backup Job Execution via wp-cron.php

Description

The plugin does not verify that a request to its cron-triggered backup execution handler actually originates from WordPress's internal scheduled-event dispatch, allowing unauthenticated attackers to force any existing backup job to run immediately, independent of its configured trigger type or schedule.

Proof of Concept

Affects Plugins

Fixed in 5.7.7

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Duy Tran
Submitter
Duy Tran
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-10-06 (about 2 days ago)
Added
2026-10-06 (about 1 day ago)
Last Updated
2026-10-06 (about 1 day ago)

Other