Executive brief
The GWD Connect plugin for WordPress, which is used to manage site backups and logs, contains a security flaw that could allow unauthorized individuals to run code on a website's server. This issue occurs on sites where the plugin has been installed but not yet fully configured with an API key. If exploited, an attacker could potentially take control of the website or access sensitive server data.
Technical details
The GWD Connect plugin for WordPress is vulnerable to missing authorization in its standalone agent endpoints, gwd-backup.php and gwd-logs.php. This vulnerability exists because these endpoints fail to verify authentication when the API key is in its default, unconfigured state. An unauthenticated remote attacker can exploit this by sending a request with the update_agent action, which allows them to write arbitrary PHP code into the agent file. This results in remote code execution, although the attack is limited to unregistered installations in specific environments where these standalone files are accessible.
Affected products
- Graphic Web Design Inc. GWD Connect Up to and including 2.9
Timeline
- 2026-05-12: advisory: Initial disclosure by Wordfence and NVD publication.
References
- https://plugins.trac.wordpress.org/browser/graphic-web-design-inc/tags/2.9/gwd-backup.php?marks=1991,2002,2548
- https://plugins.trac.wordpress.org/browser/graphic-web-design-inc/tags/2.9/gwd-logs.php?marks=398,403,851
- https://www.wordfence.com/threat-intel/vulnerabilities/id/4d2d435f-d6ce-41bd-8a45-e252fb4ba419?source=cve