{"cve":"CVE-2026-10795","enrichment":{"affected":[{"configurations":[{"platform":null,"status":"affected","versions":{"scheme":"semver","value":"[0,1.26.4]"}}],"enrichment":{"confidence":100.0,"confidence_source":"cna","scores":[{"score":100.0,"source":"cna"}]},"original":{"product":"UpdraftPlus: WP Backup & Migration Plugin","source":"cna","vendor":"davidanderson"},"product":"updraftplus:_wp_backup_&_migration_plugin","vendor":"davidanderson"},{"configurations":[{"platform":null,"status":"unaffected","versions":null}],"enrichment":{"confidence":80.0,"confidence_source":"inferred","scores":[{"score":80.0,"source":"inferred"},{"score":100.0,"source":"matching"}]},"product":"wordpress","vendor":"wordpress"}],"created":"2026-06-11T07:30:08.604950+00:00","updated":"2026-06-24T12:15:05.263800+00:00","vendors":["davidanderson","davidanderson$PRODUCT$updraftplus:_wp_backup_&_migration_plugin","wordpress","wordpress$PRODUCT$wordpress"]},"epss":{"score":0.03635},"mitre":{"cpes":[],"created":"2026-06-11T05:34:20.360000+00:00","description":"The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.4 via the UpdraftPlus_Remote_Communications_V2::wp_loaded function. This is due to insufficient validation of the remote communications message format, where signature verification can be bypassed and unchecked decryption return values collapse to a predictable all-zero encryption key. This makes it possible for unauthenticated attackers to forge arbitrary RPC commands and run them as the connected administrator, such as uploading and activating a malicious plugin, which ultimately leads to remote code execution.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":8.1,"vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"mitre_repo_path":"cves/2026/10xxx/CVE-2026-10795.json","references":["https://plugins.svn.wordpress.org/updraftplus/tags/1.26.4/vendor/team-updraft/common-libs/src/updraft-rpc/class-udrpc.php","https://plugins.svn.wordpress.org/updraftplus/tags/1.26.4/vendor/team-updraft/common-libs/src/updraft-rpc/class-udrpc2.php","https://plugins.trac.wordpress.org/changeset/3561938/updraftplus/trunk/vendor/team-updraft/common-libs/src/updraft-rpc/class-udrpc2.php","https://www.wordfence.com/threat-intel/vulnerabilities/id/e901c2a0-2477-4b9a-8483-6002419e0a2f?source=cve"],"title":"UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication Bypass via UpdraftCentral udrpc","updated":"2026-06-11T14:37:38.538000+00:00","vendors":[],"weaknesses":["CWE-347"]},"nvd":{"cpes":[],"created":"2026-06-11T07:16:26.713000+00:00","description":"The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.4 via the UpdraftPlus_Remote_Communications_V2::wp_loaded function. This is due to insufficient validation of the remote communications message format, where signature verification can be bypassed and unchecked decryption return values collapse to a predictable all-zero encryption key. This makes it possible for unauthenticated attackers to forge arbitrary RPC commands and run them as the connected administrator, such as uploading and activating a malicious plugin, which ultimately leads to remote code execution.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":8.1,"vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"nvd_repo_path":"2026/CVE-2026-10795.json","references":["https://plugins.svn.wordpress.org/updraftplus/tags/1.26.4/vendor/team-updraft/common-libs/src/updraft-rpc/class-udrpc.php","https://plugins.svn.wordpress.org/updraftplus/tags/1.26.4/vendor/team-updraft/common-libs/src/updraft-rpc/class-udrpc2.php","https://plugins.trac.wordpress.org/changeset/3561938/updraftplus/trunk/vendor/team-updraft/common-libs/src/updraft-rpc/class-udrpc2.php","https://www.wordfence.com/threat-intel/vulnerabilities/id/e901c2a0-2477-4b9a-8483-6002419e0a2f?source=cve"],"title":null,"updated":"2026-07-23T09:10:00.113000+00:00","vendors":[],"weaknesses":["CWE-347"]},"opencve":{"changes":[{"created":"2026-06-11T06:45:00+00:00","data":[{"details":{"new":"The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.4 via the UpdraftPlus_Remote_Communications_V2::wp_loaded function. This is due to insufficient validation of the remote communications message format, where signature verification can be bypassed and unchecked decryption return values collapse to a predictable all-zero encryption key. This makes it possible for unauthenticated attackers to forge arbitrary RPC commands and run them as the connected administrator, such as uploading and activating a malicious plugin, which ultimately leads to remote code execution.","old":null},"type":"description"},{"details":{"new":"UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication Bypass via UpdraftCentral udrpc","old":null},"type":"title"},{"details":{"added":["CWE-347"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://plugins.svn.wordpress.org/updraftplus/tags/1.26.4/vendor/team-updraft/common-libs/src/updraft-rpc/class-udrpc.php","https://plugins.svn.wordpress.org/updraftplus/tags/1.26.4/vendor/team-updraft/common-libs/src/updraft-rpc/class-udrpc2.php","https://plugins.trac.wordpress.org/changeset/3561938/updraftplus/trunk/vendor/team-updraft/common-libs/src/updraft-rpc/class-udrpc2.php","https://www.wordfence.com/threat-intel/vulnerabilities/id/e901c2a0-2477-4b9a-8483-6002419e0a2f?source=cve"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":8.1,"vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"9433ebb1-4c06-4eff-9295-648235b4a426"},{"created":"2026-06-11T10:45:00+00:00","data":[{"details":["davidanderson","davidanderson$PRODUCT$updraftplus:_wp_backup_&_migration_plugin","wordpress","wordpress$PRODUCT$wordpress"],"type":"first_time"},{"details":{"added":["davidanderson","davidanderson$PRODUCT$updraftplus:_wp_backup_&_migration_plugin","wordpress","wordpress$PRODUCT$wordpress"],"removed":[]},"type":"vendors"}],"id":"bb3e9565-4fdc-4016-a812-d303203af2b0"},{"created":"2026-06-11T15:30:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"0e7595dc-ca3e-4c58-ad26-484992512186"}],"cpes":{"data":[],"providers":[]},"created":{"data":"2026-06-11T05:34:20.360000+00:00","provider":"mitre"},"description":{"data":"The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.4 via the UpdraftPlus_Remote_Communications_V2::wp_loaded function. This is due to insufficient validation of the remote communications message format, where signature verification can be bypassed and unchecked decryption return values collapse to a predictable all-zero encryption key. This makes it possible for unauthenticated attackers to forge arbitrary RPC commands and run them as the connected administrator, such as uploading and activating a malicious plugin, which ultimately leads to remote code execution.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":8.1,"vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.03635},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://plugins.svn.wordpress.org/updraftplus/tags/1.26.4/vendor/team-updraft/common-libs/src/updraft-rpc/class-udrpc.php","https://plugins.svn.wordpress.org/updraftplus/tags/1.26.4/vendor/team-updraft/common-libs/src/updraft-rpc/class-udrpc2.php","https://plugins.trac.wordpress.org/changeset/3561938/updraftplus/trunk/vendor/team-updraft/common-libs/src/updraft-rpc/class-udrpc2.php","https://www.wordfence.com/threat-intel/vulnerabilities/id/e901c2a0-2477-4b9a-8483-6002419e0a2f?source=cve"],"providers":["mitre","nvd"]},"title":{"data":"UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication Bypass via UpdraftCentral udrpc","provider":"mitre"},"updated":{"data":"2026-06-11T14:42:47.007000+00:00","provider":"nvd"},"vendors":{"data":["davidanderson","davidanderson$PRODUCT$updraftplus:_wp_backup_&_migration_plugin","wordpress","wordpress$PRODUCT$wordpress"],"providers":["enrichment"]},"weaknesses":{"data":["CWE-347"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2026-06-11T05:34:20.360000+00:00","description":"The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.4 via the UpdraftPlus_Remote_Communications_V2::wp_loaded function. This is due to insufficient validation of the remote communications message format, where signature verification can be bypassed and unchecked decryption return values collapse to a predictable all-zero encryption key. This makes it possible for unauthenticated attackers to forge arbitrary RPC commands and run them as the connected administrator, such as uploading and activating a malicious plugin, which ultimately leads to remote code execution.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"references":[],"title":"UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication Bypass via UpdraftCentral udrpc","updated":"2026-06-11T14:37:28.713000+00:00","vendors":[],"vulnrichment_repo_path":"2026/10xxx/CVE-2026-10795.json","weaknesses":[]}}