PT-2026-20623 · WordPress · Backup/Restore Wordpress – Backup Plugin

Rafał

·

Published

2026-02-19

·

Updated

2026-02-23

·

CVE-2025-15041

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BackWPup – WordPress Backup & Restore Plugin versions prior to 5.6.3
Description The BackWPup – WordPress Backup & Restore Plugin for WordPress is susceptible to unauthorized data modification, potentially leading to privilege escalation. A missing capability check within the save site option() function allows authenticated attackers with a level of access and above to modify arbitrary options on a WordPress site. This can be exploited to elevate privileges, for example, by changing the default registration role to administrator and enabling user registration, thereby granting attackers administrative access.
Recommendations Update BackWPup – WordPress Backup & Restore Plugin to version 5.6.3 or later.

Fix

LPE

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-15041

Affected Products

Backup/Restore Wordpress – Backup Plugin