CRITICAL 10.0 CVE-2026-101148 Published 1 Oct 2026

BackupSheep WordPress Backup Plugin Authentication Bypass Vulnerability

Worried this affects your website?

The BackupSheep WordPress Backup Plugin through version 1.8 contains an improper integration key validation flaw. An unset or blank integration key is treated as valid, allowing unauthenticated attackers to access backup functionality.

  • Create and download full site backups, including the database with user password hashes.
  • Delete arbitrary files on the server.
  • Sensitive data disclosure and site takeover.

The plugin has been closed on WordPress.org since July 2024 and no fixed version is available. Remove it from any site where it is installed.

Reference: CVE-2026-101148 on NVD

← Back to Security News