CVE-2026-4031Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Database Backup for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.2. This is due to the plugin not restricting access to the wp_db_temp_dir parameter, which controls where database backups are written. This makes it possible for unauthenticated attackers to send a request to wp-cron.php with a poisoned wp_db_temp_dir value pointing to a publicly accessible directory (e.g., wp-content/uploads/), and if a scheduled backup is due, intercept the backup file before it is cleaned up. The backup file has a predictable name based on the database name, table prefix, date, and Swatch Internet Time, making interception reliable. Successful exploitation leads to Sensitive Information Exposure including database credentials, user password hashes, and personally identifiable information. This vulnerability requires that the site administrator has configured scheduled backups.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-25); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-25: 1Mentions · 2026-05-14: 1Technical Details · 2026-03-25: 1Technical Details · 2026-05-14: 103-2505-14
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-4031 The Database Backup for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and… CVSS 7.5 Full analysis → https://sec.kaitan.id/cves/CVE-2026-4031 #WordPress #CyberSecurity #InfoSec

    Post summary

    The post announces CVE-2026-4031, an authorization bypass flaw in the Database Backup for WordPress plugin with a CVSS of 7.5, and links to a detailed analysis.

    0000043
    90 followersView on X
  • Wasteland@wastelandweekly
    Disclosure

    CVE-2026-4031: Researchers just broke Intel TDX and AMD SEV-SNP with cross-VM side-channel attacks. The isolation that confidential computing is built on? Leaking via cache timing. Cloud-native security assumptions need a hard reset. #InfoSec

    Post summary

    The post announces the discovery of a new side‑channel vulnerability affecting Intel TDX and AMD SEV‑SNP, detailing the exploitation technique but without revealing PoC code, patches, or live exploitation evidence.

    0000052
    10 followersView on X

Explore more