CVE-2026-10795
UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication Bypass via UpdraftCentral udrpc
Description
The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.4 via the UpdraftPlus_Remote_Communications_V2::wp_loaded function. This is due to insufficient validation of the remote communications message format, where signature verification can be bypassed and unchecked decryption return values collapse to a predictable all-zero encryption key. This makes it possible for unauthenticated attackers to forge arbitrary RPC commands and run them as the connected administrator, such as uploading and activating a malicious plugin, which ultimately leads to remote code execution.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sitesen·The Hacker News· Exploited PushEngage supply-chain
- Critical UpdraftPlus CVE-2026-10795 Exploit Targets Millionsen-us·Daily CyberSecurity (securityonline.info)· Exploited UpdraftPlus (UpdraftCentral integration) auth-bypass
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-10795 and every CVE in our database. Create a free account — no credit card required.
Create Free Account