CVE-2026-76549

Published: Ago 27, 2026 Last Modified: Ago 27, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one of its backup management actions, which could allow attackers to make a logged in admin restore an existing backup, reverting the site's database and files to an earlier state, via a crafted link.

https://wpscan.com/vulnerability/59c01fb9-d651-40ec-b2c1-4b8fe386eb75/