BackWPup – WordPress Backup & Restore Plugin <= 5.7.6 - Unauthenticated Sensitive Information Exposure via Predictable Restore Working Directory
- ID
- WPSEC-2026-0502
- Plugin
- BackWPup – WordPress Backup & Restore Plugin (backwpup)
- Affected
- from 4.1.0 before 5.7.7
- Remediation
- Update to 5.7.7 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- Weakness
- CWE-552
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
- Attack surface
- BackWPup – WordPress Backup & Restore Plugin on WPSec AttackSurface
- Fix released
- Published
Description
The BackWPup plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 4.1.0 up to, and including, 5.7.6. This is due to the restore feature keeping its working files in the fixed, predictable directory wp-content/uploads/backwpup-restore/ and relying on .htaccess rules to block web access to them. Once an administrator starts a restore, this directory holds the uploaded backup archive, the extracted backup including its database dump, a restore log, and the restore.dat registry file, which from the database step onward contains the site's database credentials in plain text and the paths to the archive and the dump. This makes it possible for unauthenticated attackers to download these files on web servers that do not honour .htaccess rules, such as NGINX, while a restore is in progress, or afterwards if the restore was interrupted or abandoned. In versions before 5.7.4 the files also remained after a completed restore.
References
- https://wpsec.com/vuln/WPSEC-2026-0502/
- https://plugins.svn.wordpress.org/backwpup/tags/5.7.7/
- https://wordpress.org/plugins/backwpup/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS