External risk intelligence

BackupSheep WordPress Plugin Unauthenticated Backup Creation and File Deletion

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-101148

The vulnerability affects a WordPress plugin, which is typically installed on web-accessible servers. Because WordPress sites are commonly deployed as public-facing web applications, the affected functionality is often reachable over the internet.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the BackupSheep WordPress Backup Plugin, allowing unauthenticated attackers to create and download full site backups, access sensitive user data including password hashes, and delete arbitrary files. This could lead to significant data disclosure and complete website compromise.

  • Unauthenticated backups and file deletion possible.
  • Affects WordPress sites using the plugin.
  • Confirm plugin use and remove immediately.

Attack Path

How an attacker could exploit the issue

An attacker can target a WordPress site using the BackupSheep plugin by exploiting a weakness in how the plugin handles its integration key. If this key is not set or is left blank, the attacker can trigger the plugin's backup functionality without needing any login credentials. This allows them to create and download complete backups of the site, which could include sensitive information like user password hashes, and also to delete files, potentially leading to a complete takeover of the website.

  • Unauthenticated access to the plugin.
  • Unset or blank integration key.
  • Site takeover and data disclosure.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to create and download full site backups, which may contain sensitive data like user password hashes, and to delete files on the server.

  • Site backups and sensitive data.
  • Unauthenticated access to plugin functionality.
  • Sensitive data disclosure and site takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in the BackupSheep WordPress Backup Plugin affects the integrity and confidentiality of WordPress sites. Website owners and the teams managing their web infrastructure are primarily responsible for addressing this issue. The immediate first step is to identify all instances of this plugin, confirm if they are active and exposed, and then proceed with removal as no patch is available.

  • Website owners own this vulnerability.
  • Verify plugin installations and exposure.
  • Remove the plugin from all sites.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the BackupSheep WordPress Backup Plugin?

The BackupSheep plugin is an extension designed for WordPress websites to automate and manage site backups. It enables administrators to save copies of their database and files to offsite storage. Because it handles full site archives, it requires deep access to site data, making it a critical component for disaster recovery but a high-value target if left unmanaged.

What does CWE-73 mean for CVE-2026-101148?

CVE-2026-101148 is categorized under CWE-73, which involves improper control of file names or paths. In this specific case, the plugin fails to properly validate its integration key. By accepting a blank or unset key as valid, the software allows unauthorized users to manipulate server files and trigger backup functions that should be restricted to authenticated administrators.

How can an attacker trigger this vulnerability?

An attacker exploits this bug by interacting with the plugin's backup process without providing any login credentials. The vulnerability is triggered specifically when the integration key is left blank or unset. It is important to note that even if you have not configured the plugin or initialized the key, the installation itself remains inherently vulnerable to these unauthorized requests.

Why should I care if my site uses this plugin?

According to Halo Surface Signal, this vulnerability is classified as likely to be reachable because WordPress sites are typically deployed as public-facing applications. Since the plugin operates on a web-accessible server, an attacker on the internet can interact with it directly. This bypasses typical login protections, exposing your site's full database and administrative controls to external threats.

What should I do to secure my WordPress site?

Since there is no available patch or update for this software, you must immediately remove the BackupSheep plugin from your WordPress installation. Start by auditing your sites to identify where it is currently active. Deleting the plugin entirely is the only way to eliminate the risk of unauthenticated file deletion and unauthorized access to your site's sensitive data.

References