SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-76549

MEDIUM · CVSS 5.9 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The UpdraftPlus: WP Backup & Migration Plugin for WordPress versions prior to 1.26.7 lacks proper CSRF checks in its backup management actions, making it vulnerable to exploitation. This flaw could allow an attacker to trick a logged-in admin into restoring a backup, potentially reverting the site's database and files to a previous state, which could lead to data loss or unauthorized changes. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-76549
Severity
MEDIUM
CVSS
5.9
EPSS
0.10%
WordPress

Original NVD Description

The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one of its backup management actions, which could allow attackers to make a logged in admin restore an existing backup, reverting the site's database and files to an earlier state, via a crafted link.