Executive brief
The Royal WordPress Backup & Restore Plugin, used for managing website backups, is vulnerable to a security flaw that allows attackers to run malicious scripts in an administrator's browser. To exploit this, an attacker must trick a site administrator into clicking a specially crafted link. If successful, the attacker could potentially perform unauthorized actions on the website or steal sensitive session information.
Technical details
The Royal WordPress Backup & Restore Plugin (versions <= 1.0.16) contains a reflected cross-site scripting (XSS) vulnerability due to insufficient input validation and output escaping on the 'wpr_pending_template' parameter. An unauthenticated remote attacker can exploit this by crafting a malicious URL containing a script payload and tricking a privileged user, such as an administrator, into clicking it. The script executes within the context of the victim's browser session, potentially allowing for session hijacking or unauthorized administrative actions. The issue is addressed in version 1.0.17.
Affected products
- Royal WordPress Backup & Restore Plugin Royal WordPress Backup & Restore Plugin Up to, and including, 1.0.16
Timeline
- 2026-04-10: disclosed
- 2026-04-10: advisory
References
- https://plugins.trac.wordpress.org/browser/royal-backup-reset/tags/1.0.16/assets/backup-reminder.js
- https://plugins.trac.wordpress.org/browser/royal-backup-reset/tags/1.0.16/royal-backup-reset.php
- https://plugins.trac.wordpress.org/changeset?old_path=%2Froyal-backup-reset/tags/1.0.16&new_path=%2Froyal-backup-reset/tags/1.0.17
- https://www.wordfence.com/threat-intel/vulnerabilities/id/f9e0c658-b37c-4780-9589-6def9e36539b?source=cve