Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.2
BackWPup Plugin for WordPress Allows Attackers to Gain Admin Access
CVE-2025-15041
Summary
The BackWPup plugin for WordPress contains a security flaw that lets attackers with some level of access change important settings on your site. This could allow them to make all new users on the site have administrative access, effectively giving them control over your site. Update the plugin to the latest version to fix this issue.
Original title
The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on t...
Original description
The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the save_site_option() function in all versions up to, and including, 5.6.2. This makes it possible for authenticated attackers, with level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.
nvd CVSS3.1
7.2
Vulnerability type
CWE-862
Missing Authorization
Published: 19 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026