WP Clinic
Log in Sign up

CVE · High

CVE-2026-10795 — UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.26.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-10795 UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.26.5 Improper Verification of Cryptographic Signature High 8.1 < 1.26.5 1.26.5 2026-06-10

CVE-2026-10795

The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.4 (free) and versions up to 2.26.5 (premium) via the UpdraftPlus_Remote_Communications_V2::wp_loaded function. This is due to insufficient validation of the remote communications message format, where signature verification can be bypassed and unchecked decryption return values collapse to a predictable all-zero encryption key. This makes it possible for unauthenticated attackers to forge arbitrary RPC commands and run them as the connected administrator, such as uploading and activating a malicious plugin, which ultimately leads to remote code execution.

Source: Wordfence

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.