CVE-2026-10795
A vulnerability exists in the UpdraftPlus WordPress plugin, affecting versions up to 1.26.4 (free) and 2.26.5 (premium), where an attacker can bypass authentication and execute arbitrary RPC commands as the administrator. This is due to inadequate validation of remote communications messages, allowing an attacker to forge commands and upload malicious plugins, ultimately leading to remote code execution. The issue arises from a predictable encryption key being used, which can be exploited by an unauthenticated attacker.
Based on public CVE data (MITRE/NVD).