{
 "id": "WPSEC-2026-0502",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0502/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0502/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0502/index.md",
 "title": "BackWPup – WordPress Backup & Restore Plugin <= 5.7.6 - Unauthenticated Sensitive Information Exposure via Predictable Restore Working Directory",
 "description": "The BackWPup plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 4.1.0 up to, and including, 5.7.6. This is due to the restore feature keeping its working files in the fixed, predictable directory wp-content/uploads/backwpup-restore/ and relying on .htaccess rules to block web access to them. Once an administrator starts a restore, this directory holds the uploaded backup archive, the extracted backup including its database dump, a restore log, and the restore.dat registry file, which from the database step onward contains the site's database credentials in plain text and the paths to the archive and the dump. This makes it possible for unauthenticated attackers to download these files on web servers that do not honour .htaccess rules, such as NGINX, while a restore is in progress, or afterwards if the restore was interrupted or abandoned. In versions before 5.7.4 the files also remained after a completed restore.",
 "plugin": {
  "slug": "backwpup",
  "name": "BackWPup – WordPress Backup & Restore Plugin",
  "full_name": "BackWPup – WordPress Backup & Restore Plugin",
  "wordpress_org": "https://wordpress.org/plugins/backwpup/",
  "advisories_url": "https://wpsec.com/vuln/plugin/backwpup/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/backwpup"
 },
 "type": "SENSITIVE DATA DISCLOSURE",
 "cwe": [
  "CWE-552"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.9,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "4.1.0",
    "from_inclusive": true,
    "to": "5.7.7",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 4.1.0 before 5.7.7"
  ]
 },
 "introduced_in": "4.1.0",
 "fixed_in": "5.7.7",
 "remediation": "Update to 5.7.7 or later.",
 "fix_released": "2026-10-05T10:14:24+00:00",
 "published": "2026-10-07T11:46:41+00:00",
 "updated": "2026-10-07T10:53:23.064784+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0502/",
  "https://plugins.svn.wordpress.org/backwpup/tags/5.7.7/",
  "https://wordpress.org/plugins/backwpup/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/backwpup",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-07"
 }
}