CVE-2026-86827
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Oct 08, 2026
Vendor
unknown
Description
The BackWPup WordPress plugin before 5.7.7 does not verify that a request to its cron-triggered backup execution handler actually originates from WordPress's internal scheduled-event dispatch, allowing unauthenticated attackers to force any existing backup job to run immediately, independent of its configured trigger type or schedule.