Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 11 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Davidanderson
Davidanderson updraftplus: Wp Backup & Migration Plugin Wordpress Wordpress wordpress |
|
| Vendors & Products |
Davidanderson
Davidanderson updraftplus: Wp Backup & Migration Plugin Wordpress Wordpress wordpress |
Thu, 11 Jun 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.4 via the UpdraftPlus_Remote_Communications_V2::wp_loaded function. This is due to insufficient validation of the remote communications message format, where signature verification can be bypassed and unchecked decryption return values collapse to a predictable all-zero encryption key. This makes it possible for unauthenticated attackers to forge arbitrary RPC commands and run them as the connected administrator, such as uploading and activating a malicious plugin, which ultimately leads to remote code execution. | |
| Title | UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication Bypass via UpdraftCentral udrpc | |
| Weaknesses | CWE-347 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-06-11T14:37:38.538Z
Reserved: 2026-06-03T21:07:44.434Z
Link: CVE-2026-10795
Updated: 2026-06-11T14:37:28.713Z
Status : Deferred
Published: 2026-06-11T07:16:26.713
Modified: 2026-06-11T14:42:47.007
Link: CVE-2026-10795
No data.
OpenCVE Enrichment
Updated: 2026-06-24T12:15:05Z