Junglewise Threat Intelligence

CVE-2026-81804: ZHBackup Backup Restore Migration unauthenticated sensitive data exposure

CVE-2026-81804 · Severity: high · CVSS 7.5 · Published 2026-09-10

Executive brief

ZHBackup is a WordPress plugin that enables users to backup, restore, and migrate their website data. An unauthenticated vulnerability allows attackers to access sensitive data including passwords, emails, and payment details without authentication. This could expose customer and administrative credentials, leading to account takeover and potential data theft.

Technical details

The ZHBackup plugin versions up to 2.4.2 contain an unauthenticated sensitive data exposure vulnerability classified as OWASP A3: Sensitive Data Exposure. The vulnerability permits attackers without authentication to access private information such as passwords, emails, and payment details. The attack vector is network-based and requires no authentication or user interaction. The vulnerability is fixed in version 2.4.3 and later.

Affected products

  • ZHBackup ZHBackup – Backup, Restore & Migration <=2.4.2

Timeline

  • 2026-09-10: disclosed
  • 2026-09-09: advisory
  • 2026-09-10: patched: Fixed in version 2.4.3

References