CRITICAL 10.0 NVD

CVE-2026-101148

The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, wh

The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, including the database with user password hashes, and to delete arbitrary files on the server, leading to sensitive data disclosure and site takeover. The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 has been closed on WordPress.org since July 2024 and no fixed version is available. Remove it from any site where it is installed.

References

Published: 2026-10-01 · Source: NVD · Feed updated: 2026-10-01
This critical severity vulnerability with a CVSS score of 10.0 was published on 2026-10-01 via NVD.

Risk Timeline

CVE Disclosed2026-10-01 · -1 days ago

Remediation Resources

vulnfeed aggregates 12641 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.