
🚨Critical - BackupSheep Unauth Backup Download + Arbitrary File Delete (CVE-2026-101148) BackupSheep WordPress Backup Plugin <=1.8 fails to validate the integration key, treating a blank/unset key as valid. Unauthenticated attackers can hit the plugin’s backup/export endpoints to generate/download full site backups (incl. DB + password hashes) and invoke file delete actions, enabling data theft and potential takeover. 👉Affected: BackupSheep WordPress Backup Plugin <= 1.8
