S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2026-10795

8.1
CVSShigh
Exploitable remotely over the internet · no authentication required.
Description

The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.4 via the UpdraftPlus_Remote_Communications_V2::wp_loaded function. This is due to insufficient validation of the remote communications message format, where signature verification can be bypassed and unchecked decryption return values collapse to a predictable all-zero encryption key. This makes it possible for unauthenticated attackers to forge arbitrary RPC commands and run them as the connected administrator, such as uploading and activating a malicious plugin, which ultimately leads to remote code execution.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
updraftplus: wp backup & migration plugin
Updated Sep 22, 2026View on NVD →
S4E scanner

UpdraftPlus WP Backup & Migration Plugin Authentication Bypass Scanner

Detects 'Authentication Bypass' vulnerability in UpdraftPlus WP Backup & Migration Plugin affects v. <= 1.26.4. This scanner identifies insufficient validation issues that allow attackers to execute arbitrary commands.

Used 2.7k times · 5.9k assets checked · domain, subdomain, ipv4

CVE history: updraftplus: wp backup & migration plugin

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →