BackWPup – WordPress Backup & Restore Plugin <= 5.7.6 - Unauthenticated Sensitive Information Exposure via Predictable Restore Working Directory

Medium 5.9 CWE-552Fixed in 5.7.7
ID
WPSEC-2026-0502
Plugin
BackWPup – WordPress Backup & Restore Plugin (backwpup)
Affected
from 4.1.0 before 5.7.7
Remediation
Update to 5.7.7 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness
CWE-552
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
BackWPup – WordPress Backup & Restore Plugin on WPSec AttackSurface
Fix released
Published

Description

The BackWPup plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 4.1.0 up to, and including, 5.7.6. This is due to the restore feature keeping its working files in the fixed, predictable directory wp-content/uploads/backwpup-restore/ and relying on .htaccess rules to block web access to them. Once an administrator starts a restore, this directory holds the uploaded backup archive, the extracted backup including its database dump, a restore log, and the restore.dat registry file, which from the database step onward contains the site's database credentials in plain text and the paths to the archive and the dump. This makes it possible for unauthenticated attackers to download these files on web servers that do not honour .htaccess rules, such as NGINX, while a restore is in progress, or afterwards if the restore was interrupted or abandoned. In versions before 5.7.4 the files also remained after a completed restore.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0