GHSA-5547-r7f3-wcccMediumCVSS 6.6

The BackWPup WordPress plugin before 5.7.7 does not properly restrict the destination path of...

Published
October 8, 2026
Last Modified
October 8, 2026

🔗 CVE IDs covered (1)

📋 Description

The BackWPup WordPress plugin before 5.7.7 does not properly restrict the destination path of files extracted during a backup restore when its fallback archive library is used, allowing high-privileged users to write files outside the intended restore directory, potentially leading to remote code execution.

🔗 References (3)