Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 11 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Davidanderson
Davidanderson updraftplus: Wp Backup & Migration Plugin Wordpress Wordpress wordpress |
|
| Vendors & Products |
Davidanderson
Davidanderson updraftplus: Wp Backup & Migration Plugin Wordpress Wordpress wordpress |
Thu, 11 Jun 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.4 via the UpdraftPlus_Remote_Communications_V2::wp_loaded function. This is due to insufficient validation of the remote communications message format, where signature verification can be bypassed and unchecked decryption return values collapse to a predictable all-zero encryption key. This makes it possible for unauthenticated attackers to forge arbitrary RPC commands and run them as the connected administrator, such as uploading and activating a malicious plugin, which ultimately leads to remote code execution. | |
| Title | UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication Bypass via UpdraftCentral udrpc | |
| Weaknesses | CWE-347 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-06-11T14:37:38.538Z
Reserved: 2026-06-03T21:07:44.434Z
Link: CVE-2026-10795
Updated: 2026-06-11T14:37:28.713Z
Status : Deferred
Published: 2026-06-11T07:16:26.713
Modified: 2026-06-11T14:42:47.007
Link: CVE-2026-10795
No data.
OpenCVE Enrichment
Updated: 2026-06-11T10:40:08Z