SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-19453

HIGH · CVSS 7.1 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The JetBackup plugin for WordPress prior to version 3.1.23.5 contains a vulnerability that allows a subscriber-level user to obtain administrator privileges during site restoration or migration due to insufficient verification of user roles and capabilities. This flaw poses a significant security risk, as it can lead to unauthorized access and potential site compromise. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this high-severity risk.

CVE
CVE-2026-19453
Severity
HIGH
CVSS
7.1
EPSS
0.19%
WordPress

Original NVD Description

The JetBackup WordPress plugin before 3.1.23.5 does not verify the role or capabilities of the account it preserves across a restore or migration before granting it administrator privileges, allowing a subscriber-level user to gain administrator access after the site owner restores or migrates the site.