CVE-2026-82841: CWE-200 Information Exposure in UpdraftPlus: WP Backup & Migration Plugin
The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.8, UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 2.26.8.26 does not have any capability check in a routine that outputs its stored remote storage settings into admin pages when the site is left in a particular post-migration state, allowing any authenticated user, such as a subscriber, to retrieve the credentials of the configured backup destinations, such as passwords and secret keys.
AI Analysis
Technical Summary
The UpdraftPlus WordPress plugin versions >=1.23.8 and <1.26.8, and >=2.23.8 and <2.26.8.26, contain a vulnerability where a routine outputs stored remote storage settings without verifying user capabilities. When the site is left in a particular post-migration state, this lack of access control enables any authenticated user to retrieve sensitive credentials configured for backup destinations. This constitutes an information exposure classified under CWE-200.
Potential Impact
Any authenticated user, including those with minimal privileges such as subscribers, can obtain sensitive credentials for remote backup storage destinations. This exposure could lead to unauthorized access to backup data or remote storage services, potentially compromising site backups and sensitive information contained therein.
Mitigation Recommendations
A fixed version is implied by the version ranges given, but no explicit patch or vendor advisory is provided in the input data. Therefore, patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is confirmed, restrict authenticated user roles to trusted users only and monitor for unusual access patterns related to backup settings.
CVE-2026-82841: CWE-200 Information Exposure in UpdraftPlus: WP Backup & Migration Plugin
Description
The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.8, UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 2.26.8.26 does not have any capability check in a routine that outputs its stored remote storage settings into admin pages when the site is left in a particular post-migration state, allowing any authenticated user, such as a subscriber, to retrieve the credentials of the configured backup destinations, such as passwords and secret keys.
CVSS v3.1
Score 5.3medium
Affected software
UpdraftPlus: WP Backup & Migration Plugin
UpdraftPlus: WP Backup & Migration Plugin
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The UpdraftPlus WordPress plugin versions >=1.23.8 and <1.26.8, and >=2.23.8 and <2.26.8.26, contain a vulnerability where a routine outputs stored remote storage settings without verifying user capabilities. When the site is left in a particular post-migration state, this lack of access control enables any authenticated user to retrieve sensitive credentials configured for backup destinations. This constitutes an information exposure classified under CWE-200.
Potential Impact
Any authenticated user, including those with minimal privileges such as subscribers, can obtain sensitive credentials for remote backup storage destinations. This exposure could lead to unauthorized access to backup data or remote storage services, potentially compromising site backups and sensitive information contained therein.
Mitigation Recommendations
A fixed version is implied by the version ranges given, but no explicit patch or vendor advisory is provided in the input data. Therefore, patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is confirmed, restrict authenticated user roles to trusted users only and monitor for unusual access patterns related to backup settings.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-08-31T08:21:45.873Z
- State
- PUBLISHED
Threat ID: 6ab8b2d5f7a7c54106aa92d3
Added to database: 09/27/2026, 06:08:21 UTC
Last enriched: 09/27/2026, 06:18:37 UTC
Last updated: 09/28/2026, 01:57:30 UTC
Views: 16
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.