Junglewise Threat Intelligence

CVE-2026-65443: WP Media BackWPup unauthenticated XSS

CVE-2026-65443 · Severity: high · CVSS 7.1 · Published 2026-07-27

Executive brief

BackWPup, a popular WordPress plugin used for site backups, is vulnerable to a security flaw that allows attackers to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link, the attacker could potentially hijack sessions, redirect users to malicious sites, or deface the website. This vulnerability can be exploited by remote attackers without needing any login credentials.

Technical details

The BackWPup plugin for WordPress contains an unauthenticated Cross-Site Scripting (XSS) vulnerability in versions up to and including 5.7.4. The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). A remote, unauthenticated attacker can exploit this by tricking a user into performing an action, such as clicking a malicious link. Successful exploitation allows the attacker to execute arbitrary JavaScript in the victim's browser session, which can lead to session hijacking or unauthorized actions on behalf of a privileged user. The issue is resolved in version 5.7.5.

Affected products

  • WP Media BackWPup <= 5.7.4

Timeline

  • 2026-07-03: disclosed: Reported by researcher daroo
  • 2026-07-27: advisory: Published by Patchstack and NVD
  • 2026-07-27: patched: Fixed in version 5.7.5

References