# BackWPup – WordPress Backup & Restore Plugin <= 5.7.6 - Unauthenticated Sensitive Information Exposure via Predictable Restore Working Directory

- **ID:** WPSEC-2026-0502
- **Plugin:** BackWPup – WordPress Backup & Restore Plugin (`backwpup`), https://wordpress.org/plugins/backwpup/
- **Affected versions:** from 4.1.0 before 5.7.7
- **Fixed in:** 5.7.7 (Update to 5.7.7 or later.)
- **Severity:** Medium 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
- **Weakness:** CWE-552
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/backwpup
- **Fix released:** 2026-10-05
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0502/

## Description

The BackWPup plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 4.1.0 up to, and including, 5.7.6. This is due to the restore feature keeping its working files in the fixed, predictable directory wp-content/uploads/backwpup-restore/ and relying on .htaccess rules to block web access to them. Once an administrator starts a restore, this directory holds the uploaded backup archive, the extracted backup including its database dump, a restore log, and the restore.dat registry file, which from the database step onward contains the site's database credentials in plain text and the paths to the archive and the dump. This makes it possible for unauthenticated attackers to download these files on web servers that do not honour .htaccess rules, such as NGINX, while a restore is in progress, or afterwards if the restore was interrupted or abandoned. In versions before 5.7.4 the files also remained after a completed restore.

## References

- https://wpsec.com/vuln/WPSEC-2026-0502/
- https://plugins.svn.wordpress.org/backwpup/tags/5.7.7/
- https://wordpress.org/plugins/backwpup/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0502/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
