CVE-2026-4030 - Vulnerability Analysis
HighCVSS: 8.1Last Updated: May 14, 2026
Database Backup for WordPress - Broken Access Control
Overview
Database Backup for WordPress plugin <= 2.5.2 contains an unauthorized arbitrary file read and deletion vulnerability caused by improper authorization check enforcement and user-controlled backup directory parameter, letting unauthenticated attackers read and delete arbitrary files, exploit requires WordPress Multisite with deprecated is_site_admin() function.
Severity & Score
Impact
Unauthenticated attackers can read and delete arbitrary files, leading to sensitive information exposure and potential site takeover.
Mitigation
Update to the latest version beyond 2.5.2.
References
- https://plugins.trac.wordpress.org/browser/wp-db-backup/trunk/wp-db-backup.php#L157
- https://plugins.trac.wordpress.org/browser/wp-db-backup/trunk/wp-db-backup.php#L1632
- https://plugins.trac.wordpress.org/changeset/3510595/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/3e21b550-e1c5-4e23-9999-16c837353da9?source=cve
- https://plugins.trac.wordpress.org/browser/wp-db-backup/tags/2.5.2/wp-db-backup.php#L1623
- https://plugins.trac.wordpress.org/browser/wp-db-backup/trunk/wp-db-backup.php#L121
Social Media Activity(2 posts)
š CVE-2026-4030 - High (8.1) The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of its authorizati... š https://www.thehackerwire.com/vulnerability/CVE-2026-4030/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postš CVE-2026-4030 - High (8.1) The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of its authorizati... š https://www.thehackerwire.com/vulnerability/CVE-2026-4030/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-4030
- Severity
- High
- CVSS Score
- 8.1
- Type
- broken_access_control
- Status
- rejected
- EPSS
- 0.0%
- Social Posts
- 2
CWE
- CWE-862
CVSS Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H