Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 08 Oct 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-73 |
Thu, 08 Oct 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 08 Oct 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 CWE-73 |
Thu, 08 Oct 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The BackWPup WordPress plugin before 5.7.7 does not properly restrict the destination path of files extracted during a backup restore when its fallback archive library is used, allowing high-privileged users to write files outside the intended restore directory, potentially leading to remote code execution. | |
| Title | BackWPup < 5.7.7 - Admin+ Path Traversal to RCE via Restore PclZip Fallback | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-08T10:59:18.107Z
Reserved: 2026-09-08T14:26:00.880Z
Link: CVE-2026-86828
Updated: 2026-10-08T10:52:53.705Z
Status : Received
Published: 2026-10-08T06:16:45.287
Modified: 2026-10-08T11:16:47.027
Link: CVE-2026-86828
No data.
OpenCVE Enrichment
Updated: 2026-10-08T13:15:08Z