Executive brief
The pCloud WP Backup plugin for WordPress, which is used to create and store website backups, contains a security flaw that allows users with low-level accounts (like subscribers) to trigger a full site backup. This backup is then stored in a publicly accessible folder with a predictable name. An attacker can download this file to obtain sensitive information, including database passwords, security keys, and the website's entire source code, potentially leading to a full site takeover.
Technical details
The vulnerability exists in the wp2pcl_ajax_process_request_inner function of the pCloud WP Backup plugin due to insufficient access control on AJAX requests. Authenticated attackers with subscriber-level permissions or higher can trigger a full-site backup process. The plugin deposits the resulting archive into an unprotected 'tmp/' directory using a predictable naming convention. Because this directory is web-accessible and lacks proper authorization checks, any unauthenticated user can download the archive once it has been generated, leading to the exposure of wp-config.php, database credentials, and the full PHP source tree. A patch appears to be available in version 2.0.4 based on the changeset references.
Affected products
- ploudapp pCloud WP Backup up to, and including, 2.0.3
Timeline
- 2026-07-17: advisory: Initial disclosure by Wordfence and NVD publication
References
- https://plugins.trac.wordpress.org/browser/pcloud-wp-backup/tags/2.0.2/Pcloud/Classes/class-wp2pcloudfilebackup.php
- https://plugins.trac.wordpress.org/browser/pcloud-wp-backup/tags/2.0.2/pcloud-wp-backup.php
- https://plugins.trac.wordpress.org/browser/pcloud-wp-backup/tags/2.0.2/pcloud-wp-backup.php
- https://plugins.trac.wordpress.org/browser/pcloud-wp-backup/tags/2.0.2/pcloud-wp-backup.php
- https://plugins.trac.wordpress.org/browser/pcloud-wp-backup/tags/2.0.2/pcloud-wp-backup.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3597399%40pcloud-wp-backup&new=3597399%40pcloud-wp-backup
- https://www.wordfence.com/threat-intel/vulnerabilities/id/0b301c6e-a3c5-4435-9bc9-fab18085fe2d?source=cve