Executive brief
ZHBackup is a WordPress plugin that enables users to backup, restore, and migrate their website data. An unauthenticated vulnerability allows attackers to access sensitive data including passwords, emails, and payment details without authentication. This could expose customer and administrative credentials, leading to account takeover and potential data theft.
Technical details
The ZHBackup plugin versions up to 2.4.2 contain an unauthenticated sensitive data exposure vulnerability classified as OWASP A3: Sensitive Data Exposure. The vulnerability permits attackers without authentication to access private information such as passwords, emails, and payment details. The attack vector is network-based and requires no authentication or user interaction. The vulnerability is fixed in version 2.4.3 and later.
Affected products
- ZHBackup ZHBackup – Backup, Restore & Migration <=2.4.2
Timeline
- 2026-09-10: disclosed
- 2026-09-09: advisory
- 2026-09-10: patched: Fixed in version 2.4.3