CVE-2026-1311Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Worry Proof Backup plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.2.4 via the backup upload functionality. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload a malicious ZIP archive with path traversal sequences to write arbitrary files anywhere on the server, including executable PHP files. This can lead to remote code execution.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • Peaked 2d ago at 4 mentions (2026-02-26); latest day: 1
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-02-26: 4Mentions · 2026-03-02: 1Mentions · 2026-03-03: 1Patch / Workaround · 2026-03-02: 1Technical Details · 2026-02-26: 4Technical Details · 2026-03-02: 1Technical Details · 2026-03-03: 102-2603-0203-03
Signal classification1 categories
Disclosure
6100.0%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-02-264
Disclosure4
2026-03-021
Disclosure1
2026-03-031
Disclosure1
Full discourse6 posts
  • ThaiCERT By NCSA@ThaiCERTByNCSA
    Disclosure

    🚨ด่วน!!!! พบช่องโหว่บนเว็บไซต์ WordPress ในปลั๊กอิน Worry Proof Backup🚨 ThaiCERT ติดตามข่าวสารภัยคุกคามทางไซเบอร์ พบช่องโหว่บนเว็บไซต์ WordPress ในปลั๊กอิน Worry Proof Backup ผู้โจมตีสามารถอัปโหลดไฟล์และรันโค้ดอันตราย 1. รายละเอียดเหตุการณ์ • CVE-2026-1311 (CVSS:v3.1: 8.8) เป็นช่องโหว่ความปลอดภัย WordPress ในปลั๊กอิน Worry Proof Backup โดยพบช่องโหว่ที่ Path Traversal ผ่านฟังก์ชันอัปโหลดไฟล์สำรองข้อมูล ทำให้ผู้โจมตีที่มีสิทธิ์ในระดับ Subscriber หรือสูงกว่า สามารถอัปโหลดไฟล์ ZIP ที่มีการจัดการ path traversal และผู้โจมตีจะทำการเขียนไฟล์บนเซิร์ฟเวอร์ได้ • หากผู้โจมตีทำการเขียนไฟล์ลงเซิร์ฟเวอร์ ผู้โจมตีจะสามารถรันโค้ดอันตรายได้ (Remote Code Execution: RCE) 2. เวอร์ชันที่ได้รับผลกระทบ • WordPress ทุกเวอร์ชัน ถึง 0.2.4 3. พฤติกรรมการโจมตี • ผู้โจมตีที่มีบัญชีผู้ใช้ WordPress ในระดับ Subscriber หรือระดับที่สามารถเข้าถึงฟังก์ชันของปลั๊กอินได้ • ใช้ฟังก์ชัน backup upload ของปลั๊กอินเพื่อส่งไฟล์ ZIP ที่ path traversal • เมื่อระบบแตกไฟล์ ZIP จะเกิดการเขียนไฟล์ไปยังไดเรกทอรีสำคัญของเซิร์ฟเวอร์ • วางไฟล์สคริปต์ เช่น PHP, web shell และรันโค้ดอันตราย 4. แนวทางการป้องกันและลดความเสี่ยง 4.1 อัปเดตปลั๊กอินและปฏิบัติตามคำแนะนำของผู้พัฒนาอย่างเคร่งครัด 4.2 ตรวจสอบสิทธิ์ผู้ใช้และลดจำนวนบัญชีที่ไม่จำเป็น 4.3 จำกัดการอัปโหลดไฟล์ ดำเนินการปิดฟังก์ชันอัปโหลดไฟล์สำหรับผู้ใช้ที่มีสิทธิ์ต่ำกว่า Editor หรือ Administrator (ถ้าไม่จำเป็น) 4.4 ตั้งค่าการสแกนไฟล์อัตโนมัติ โดยการใช้ระบบป้องกันมัลแวร์และตรวจจับการเปลี่ยนแปลงไฟล์ (File Integrity Monitoring) 4.5 ปิด execution สำหรับ Directory ที่ไม่จำเป็น 4.6 ใช้ Web Application Firewall (WAF) เพื่อบล็อก payload ที่มี path traversal patterns 5. มาตรการชั่วคราว (กรณียังไม่สามารถอัปเดตได้ทันที) 5.1 ปิดการใช้งานฟีเจอร์ “Upload Backup” ในปลั๊กอินเป็นการชั่วคราว 5.2 จำกัดสิทธิ์ผู้ใช้ โดยการลดสิทธิ์ของผู้ใช้ทั่วไป ไม่ให้สามารถเข้าถึงฟังก์ชันที่มีความเสี่ยง และใช้ Two-Factor Authentication (2FA) สำหรับบัญชีที่มีสิทธิ์ระดับสูง 6. แหล่งอ้างอิง (References) 6.1 https://dg.th/uckbt9hwdz 6.1 https://dg.th/kta7ohgmu8 ทั้งนี้ หน่วยงานสามารถตรวจสอบ Plugin Directory ได้ที่ https://dg.th/jte7m0or6k และ https://dg.th/e2fp5it7bo

    Post summary

    ThaiCERT announces the discovery of CVE‑2026‑1311 in the Worry Proof Backup plugin, detailing a path‑traversal RCE vulnerability and providing mitigation guidance.

    0100054
    48 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-1311 (CVSS:8.8, HIGH) is Awaiting Analysis. The Worry Proof Backup plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.2.4 ..https://nvd.nist.gov/vuln/detail/CVE-2026-1311 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-1311, a high‑severity path traversal flaw in the Worry Proof Backup WordPress plugin, with no evidence of exploitation or mitigation yet.

    0000023
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1311 The Worry Proof Backup plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.2.4 via the backup upload functionality. This makes … https://www.cve.org/CVERecord?id=CVE-2026-1311

    Post summary

    The Worry Proof Backup plugin for WordPress is vulnerable to path traversal via the backup upload feature, affecting all versions up to 0.2.4.

    0000091
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1311 Path Traversal in Worry Proof Backup WordPress Plugin via Maliciou... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1311 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The post announces a path traversal vulnerability (CVE-2026-1311) in the Worry Proof Backup WordPress plugin, linking to a details page but providing no PoC, exploit, or patch information.

    0000044
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-1311: HIGH] WordPress's Worry Proof Backup plugin versions up to 0.2.4 have a Path Traversal vulnerability allowing attackers to upload malicious ZIP files, leading to server takeovers.#cve,CVE-2026-1311,#cybersecurity https://cvefind.com/CVE-2026-1311

    Post summary

    The post announces a high‑severity path traversal flaw in WordPress's Worry Proof Backup plugin that permits malicious ZIP uploads, potentially leading to server takeover.

    0000066
    585 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-1311** pertains to a **Path Traversal** vulnerability in the **Worry Proof Backup** plugin for WordPress, affecting all versions up to 0.2.4. This flaw resides in the plugin's backup upload functionality, allowing authenticated attackers with Subscriber-level access or higher to upload malicious ZIP archives containing path traversal sequences. Exploiting this, an attacker can write arbitrary files to the server, including executable PHP scripts, leading to **remote code execution (RCE)**. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution https://cvetodo.com/cve/CVE-2026-1311

    Post summary

    The post discloses a path traversal vulnerability in the Worry Proof Backup WordPress plugin that lets authenticated users upload malicious ZIP archives, enabling arbitrary file writes and remote code execution.

    0000044
    20 followersView on X

Explore more