CVE-2026-4853Disclosure

LOWCVSS 4.9 · MEDIUM

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The JetBackup – Backup, Restore & Migrate plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary Directory Deletion in versions up to and including 3.1.19.8. This is due to insufficient input validation on the fileName parameter in the file upload handler. The plugin sanitizes the fileName parameter using sanitize_text_field(), which removes HTML tags but does not prevent path traversal sequences like '../'. The unsanitized filename is then directly concatenated in Upload::getFileLocation() without using basename() or validating the resolved path stays within the intended directory. When an invalid file is uploaded, the cleanup logic calls dirname() on the traversed path and passes it to Util::rm(), which recursively deletes the entire resolved directory. This makes it possible for authenticated attackers with administrator-level access to traverse outside the intended upload directory and trigger deletion of critical WordPress directories such as wp-content/plugins, effectively disabling all installed plugins and causing severe site disruption.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-17: 3PoC Mentioned / Linked · 2026-04-17: 1Technical Details · 2026-04-17: 204-17
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-4853-backup-version-3-1-19-8-medium-vulnerability-proof-of-concept CVE-2026-4853 #WordPress plugin #vulnerability backup #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    The tweet shares a link to a proof‑of‑concept for CVE‑2026‑4853, a WordPress backup plugin vulnerability, but provides no evidence of active exploitation, patches, or detailed technical information.

    0000051
    7 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4853 The JetBackup – Backup, Restore & Migrate plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary Directory Deletion in versions up to and including 3… https://www.cve.org/CVERecord?id=CVE-2026-4853

    Post summary

    A new vulnerability (CVE-2026-4853) was disclosed for the JetBackup WordPress plugin, exposing a path traversal flaw that can delete arbitrary directories.

    0000065
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4853 Path Traversal Leading to Arbitrary Directory Deletion in JetBackup Plugin 3.1.19.8 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4853

    Post summary

    The post announces CVE-2026-4853, a path traversal vulnerability in JetBackup 3.1.19.8 that permits arbitrary directory deletion; it does not provide a PoC, exploit, patch, or evidence of active exploitation.

    0000032
    4.0K followersView on X

Explore more