The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 has been closed on WordPress.org since July 2024 and no fixed version is available. Remove it from any site where it is installed.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 CWE-284 |
Thu, 01 Oct 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, including the database with user password hashes, and to delete arbitrary files on the server, leading to sensitive data disclosure and site takeover. The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 has been closed on WordPress.org since July 2024 and no fixed version is available. Remove it from any site where it is installed. | |
| Title | BackupSheep <= 1.8 - Unauthenticated Arbitrary File Deletion and Backup Exfiltration via Empty Integration Key | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-01T06:00:23.265Z
Reserved: 2026-09-28T08:14:28.260Z
Link: CVE-2026-101148
No data.
Status : Received
Published: 2026-10-01T06:17:04.057
Modified: 2026-10-01T06:17:04.057
Link: CVE-2026-101148
No data.
OpenCVE Enrichment
Updated: 2026-10-01T08:15:05Z
