SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-19454

MEDIUM · CVSS 4.4 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The JetBackup WordPress plugin prior to version 3.1.23.5 lacks proper multisite authorization checks, enabling non-Super Admin network administrators to access and download full backups of all sites within the network, including sensitive data and shared webroot. This vulnerability poses a significant risk to data confidentiality and integrity across the entire WordPress multisite installation. WordPress administrators, particularly those managing multisite environments, should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-19454
Severity
MEDIUM
CVSS
4.4
EPSS
0.25%
WordPress

Original NVD Description

The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup archives and job logs, allowing an administrator of the network's main site who is not a Super Admin to download a full backup of the entire network, including every site's data and the shared webroot.