Executive brief
Trinity Backup, a WordPress plugin used for site migration and data backups, contains a security flaw that allows unauthorized individuals to access sensitive information. An attacker could exploit this to view private data that should be restricted, potentially leading to further compromise of the website or its users. This vulnerability is particularly serious because it can be exploited remotely without any login credentials.
Technical details
The Trinity Backup plugin for WordPress (versions <= 2.0.9) is vulnerable to an authorization bypass (CWE-639) that leads to sensitive data exposure. The flaw allows an unauthenticated remote attacker to access information that should be restricted to administrative users. This is likely due to insufficient access control checks on backup files or plugin-generated data. An attacker can exploit this by sending crafted network requests to the affected site to retrieve sensitive configuration or backup data. The issue is resolved in version 2.0.10.
Affected products
- kingaddons Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups <= 2.0.9
Timeline
- 2026-04-29: disclosed: Reported by researcher dodoh4t
- 2026-06-18: advisory: Patchstack advisory published
- 2026-06-26: advisory: NVD published date