Junglewise Threat Intelligence

CVE-2026-57757: ploudapp pCloud WP Backup CSRF

CVE-2026-57757 · Severity: high · CVSS 7.1 · Published 2026-07-02

Executive brief

The pCloud WP Backup plugin for WordPress, which is used to automate website backups to pCloud storage, contains a security flaw that could allow an attacker to trick a site administrator into performing unintended actions. By persuading an authorized user to click a malicious link or visit a specially crafted webpage, an attacker could potentially modify backup settings or expose sensitive data. This could lead to unauthorized access to site backups or disruption of the backup process.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the pCloud WP Backup plugin for WordPress (versions <= 2.0.2) due to insufficient validation of request origins. The vulnerability is classified as CWE-352 and allows an unauthenticated remote attacker to perform actions on behalf of a higher-privileged user. Exploitation requires the attacker to trick a logged-in administrator into interacting with a malicious link or form (User Interaction required). Successful exploitation can lead to a high impact on confidentiality and a low impact on integrity, potentially allowing attackers to manipulate backup configurations or access backup data. As of the advisory date, no official patch has been released.

Affected products

  • ploudapp pCloud WP Backup <= 2.0.2

Timeline

  • 2026-04-20: disclosed: Reported by R2D2
  • 2026-07-02: advisory: Published by Patchstack and NVD

References