CVE-2026-19454 - JetBackup 3.1.18.8 - 3.1.23.3 - Admin+ Multisite Network Backup Download
CVE ID :CVE-2026-19454
Published : Aug. 27, 2026, 6 a.m. | 29 minutes ago
Description :The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup archives and job logs, allowing an administrator of the network's main site who is not a Super Admin to download a full backup of the entire network, including every site's data and the shared webroot.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 27, 2026, 6 a.m. | 29 minutes ago
Description :The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup archives and job logs, allowing an administrator of the network's main site who is not a Super Admin to download a full backup of the entire network, including every site's data and the shared webroot.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...