216.73.217.24

CVE-2026-4030

· Published 14/05/2026 13:16 · Modified 14/05/2026 14:28

Labels: CVE-2026-4030 2026-05-14CVE-2026-4030CWE-862[email protected]

Essential information

Published
14/05/2026 13:16
Modified
14/05/2026 14:28
Author
Creator
CVSS
8.1 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of its authorization check combined with a user-controlled backup directory parameter. This makes it possible for unauthenticated attackers to read and delete arbitrary files on the server, leading to Sensitive Information Exposure and potential site takeover. Note: This vulnerability is only exploitable in WordPress Multisite environments where the deprecated is_site_admin() function exists.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
wordpress / database backup for wordpress cpe:2.3:a:wordpress:database_backup_for_wordpress:<2.5.2:*:*:*:*:wordpress:*:*

References