CVE-2026-4030HIGH 8.1EPSS p24.5%

CVE-2026-4030CVE-2026-4030

Description

The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of its authorization check combined with a user-controlled backup directory parameter. This makes it possible for unauthenticated attackers to read and delete arbitrary files on the server, leading to Sensitive Information Exposure and potential site takeover. Note: This vulnerability is only exploitable in WordPress Multisite environments where the deprecated is_site_admin() function exists.

Scoring

CVSS 3.18.1 (HIGH)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.33% probability of exploitation · percentile 24.5% · 2026-06-19T12:03:05Z
Published2026-05-14
Last modified2026-05-14

Underlying weaknesses· 1

CWE-862

References

  1. https://plugins.trac.wordpress.org/browser/wp-db-backup/tags/2.5.2/wp-db-backup.php#L1623
  2. https://plugins.trac.wordpress.org/browser/wp-db-backup/trunk/wp-db-backup.php#L121
  3. https://plugins.trac.wordpress.org/browser/wp-db-backup/trunk/wp-db-backup.php#L157
  4. https://plugins.trac.wordpress.org/browser/wp-db-backup/trunk/wp-db-backup.php#L1632
  5. https://plugins.trac.wordpress.org/changeset/3510595/
  6. https://www.wordfence.com/threat-intel/vulnerabilities/id/3e21b550-e1c5-4e23-9999-16c837353da9?source=cve

1

TypeTargetConfidenceTier
WeaknessMissing Authorizationcwe-8620%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-7565
CVE
CVE-2025-3065
CVE
CVE-2026-1104
CVE
CVE-2026-1311
CVE
CVE-2026-3464
CVE
CVE-2026-3666
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.