Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-82841— UpdraftPlus 1.23.8 - 1.26.7 - Subscriber+ Remote Storage Credential Disclosure via Migration Notice

Quick assessment

Affected
Unknown UpdraftPlus: WP Backup & Migration Plugin
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

UpdraftPlus: WP Backup & Migration WordPress 插件在 1.26.8 之前版本,以及 2.26.8.26 之前版本中,存在一个权限检查缺失的漏洞。当站点处于特定的迁移后状态时,一个用于在管理页面输出已存储的远程存储设置的例程未进行能力(capability)检查,使得任何已认证的用户(例如订阅者)都能够获取已配置的备份目标(如密码和密钥)的凭据。

AI Predicted 6.5 Difficulty: Easy EPSS 0.14% · P3
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-82841

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
UpdraftPlus 1.23.8 - 1.26.7 - Subscriber+ Remote Storage Credential Disclosure via Migration Notice
Source: CVE Program / CVE List V5
Vulnerability Description
The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.8, UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 2.26.8.26 does not have any capability check in a routine that outputs its stored remote storage settings into admin pages when the site is left in a particular post-migration state, allowing any authenticated user, such as a subscriber, to retrieve the credentials of the configured backup destinations, such as passwords and secret keys.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unknown UpdraftPlus: WP Backup & Migration Plugin 1.23.8 ~ 1.26.8 -
Unknown UpdraftPlus: WP Backup & Migration Plugin 2.23.8 ~ 2.26.8.26 -

II. Public POCs for CVE-2026-82841

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-82841

请登录查看更多情报信息。

Other References for CVE-2026-82841 (1)

Same Patch Batch · Unknown · 2026-09-27 · 19 CVEs total

CVE-2026-89006 WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Stored XSS via Feed Import
CVE-2026-84069 WebFacing Email Accounts for cPanel 5.3 - 5.3.6 - Unauthenticated LFI via assets/index.php
CVE-2026-81655 Ad Inserter 2.8.12 - 2.8.18 - Subscriber+ RCE / Stored XSS via Global Custom Fields
CVE-2026-85002 EmbedPress < 4.6.7 - Contributor+ Stored XSS via Instagram Carousel Block Attributes
CVE-2026-86609 Download Manager Pro < 7.5.6 - Unauthenticated Stored XSS via Email Lock Subscription
CVE-2026-86839 Bookly < 28.3 - Staff+ Appointment and Payment Disclosure, Modification and Deletion via I
CVE-2026-86841 Bookly 23.2 - 28.2 - Bookly Administrator+ PHP Object Injection via Diagnostics Advanced O
CVE-2026-89001 WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Post Publication and Author Spoofing vi
CVE-2026-89003 WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Preview
CVE-2026-96899 Optima Express 8.6.0 - 8.7.5 - Author+ Stored XSS via faq_script
CVE-2026-89000 WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Run
CVE-2026-96896 Malcure Malware Shield < 19.9.7 - Multisite Subsite Admin+ Arbitrary File Write and Deleti
CVE-2026-96897 Optima Express 8.5.0 - 8.7.5 - Unauthenticated Author Account Creation & Application Passw
CVE-2026-96895 WP YouTube Lyte < 1.7.31 - Contributor+ Stored XSS via Embed Block Attributes
CVE-2026-92995 Verge3D <= 4.13.0 - Unauthenticated Product Download Disclosure via v3d_download_file
CVE-2026-92436 Mailchimp for WooCommerce < 6.3 - Unauthenticated Customer Email and Cart Disclosure via I
CVE-2026-97319 PowerPress < 11.17.2 - Contributor+ Stored XSS via Podcast Player Block
CVE-2026-97227 NextScripts: Social Networks Auto-Poster < 4.4.8 - Authenticated Social Account Credential

IV. Related Vulnerabilities

V. Comments for CVE-2026-82841

No comments yet


Leave a comment