Executive brief
BackWPup is a widely-used WordPress plugin for automated website backup and recovery. The plugin fails to properly restrict access to its backup management API endpoints, allowing users assigned a limited administrative role to create database backups and redirect them to attacker-controlled locations. An attacker exploiting this could exfiltrate complete database copies containing all user credentials and sensitive site data.
Technical details
The vulnerability is an authorization bypass (CWE-862) in BackWPup's REST API routes for job, backup-destination, and backup-execution management. The routes check only for the broad "backwpup" capability that the limited "BackWPup jobs checker" role carries, rather than enforcing granular job-edit and job-start capabilities the role is explicitly denied. An authenticated user holding the limited BackWPup-defined role can call endpoints like /backwpup/v1/addjob, /backwpup/v1/updatejob, /backwpup/v1/cloudsaveandtest, and /backwpup/v1/startbackup to create database backups and exfiltrate them to an attacker-controlled email server. The vulnerability affects versions 5.2.2 through 5.7.4 and has been fixed in 5.7.5.
Affected products
- BackWPup BackWPup 5.2.2 through 5.7.4
Timeline
- 2026-09-09: disclosed
- 2026-05-25: patched: Fixed in version 5.7.5