Junglewise Threat Intelligence

CVE-2026-39480: BackupBliss Backup Migration sensitive data exposure

CVE-2026-39480 · Severity: high · CVSS 7.5 · Published 2026-06-15

Executive brief

The Backup Migration plugin for WordPress, which is used to create and move website backups, contains a security flaw that allows unauthorized individuals to access sensitive data. This could lead to the exposure of website configuration details or backup files, potentially providing attackers with the information needed to compromise the entire site. Users should update to version 2.1.2 or later to secure their installations.

Technical details

A sensitive data exposure vulnerability exists in the Backup Migration plugin for WordPress (versions <= 2.1.1) due to improper restriction of sensitive information (CWE-201). An unauthenticated remote attacker can exploit this flaw to access sensitive data, such as backup files or configuration details, without any user interaction. The vulnerability is rated with a CVSS score of 7.5, reflecting high confidentiality impact. The issue is resolved in version 2.1.2; notably, the vendor indicates that standard virtual patching may not be effective due to the nature of the flaw, making a direct software update essential.

Affected products

  • BackupBliss Backup Migration <= 2.1.1

Timeline

  • 2026-02-17: other: Reported by researcher ch4r0n
  • 2026-04-08: disclosed: Initial disclosure by Patchstack
  • 2026-06-15: advisory: NVD publication date

References