CVE-2026-1311 PUBLISHED

Worry Proof Backup <= 0.2.4 - Authenticated (Subscriber+) Path Traversal via Backup Upload

Assigner: Wordfence
Reserved: 21.01.2026 Published: 26.02.2026 Updated: 26.02.2026

The Worry Proof Backup plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.2.4 via the backup upload functionality. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload a malicious ZIP archive with path traversal sequences to write arbitrary files anywhere on the server, including executable PHP files. This can lead to remote code execution.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.8

Product Status

Vendor bearsthemes
Product Worry Proof Backup
Versions Default: unaffected
  • affected from * to 0.2.4 (incl.)

Credits

  • Athiwat Tiprasaharn finder
  • Itthidej Aramsri finder

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE