Junglewise Threat Intelligence

CVE-2026-14503: pCloud WP Backup sensitive information exposure in AJAX request handler

CVE-2026-14503 · Severity: medium · CVSS 6.5 · Published 2026-07-17

Executive brief

The pCloud WP Backup plugin for WordPress, which is used to create and store website backups, contains a security flaw that allows users with low-level accounts (like subscribers) to trigger a full site backup. This backup is then stored in a publicly accessible folder with a predictable name. An attacker can download this file to obtain sensitive information, including database passwords, security keys, and the website's entire source code, potentially leading to a full site takeover.

Technical details

The vulnerability exists in the wp2pcl_ajax_process_request_inner function of the pCloud WP Backup plugin due to insufficient access control on AJAX requests. Authenticated attackers with subscriber-level permissions or higher can trigger a full-site backup process. The plugin deposits the resulting archive into an unprotected 'tmp/' directory using a predictable naming convention. Because this directory is web-accessible and lacks proper authorization checks, any unauthenticated user can download the archive once it has been generated, leading to the exposure of wp-config.php, database credentials, and the full PHP source tree. A patch appears to be available in version 2.0.4 based on the changeset references.

Affected products

  • ploudapp pCloud WP Backup up to, and including, 2.0.3

Timeline

  • 2026-07-17: advisory: Initial disclosure by Wordfence and NVD publication

References