{"id":"CVE-2026-82841","title":"The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.8, UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 2.26.8.26 does not have any capability check in a routine that outputs its stored remote stor…","summary":"The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.8, UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 2.26.8.26 does not have any capability check in a routine that outputs its stored remote stor…","severity":"none","cwe":["CWE-200"],"product":"UpdraftPlus: WP Backup & Migration Plugin","affected":["updraftplus_wp_backup_migration_plugin >= 1.23.8 < 1.26.8","updraftplus_wp_backup_migration_plugin >= 2.23.8 < 2.26.8.26"],"published":"2026-09-27","updated":"2026-09-27","sourceUpdated":"2026-09-27T06:17:03.433","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-82841","references":[{"url":"https://wpscan.com/vulnerability/52f39a82-89ee-43f1-ba9c-3ea646fb0a0e/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-27T06:43:46.828Z","slug":"CVE-2026-82841","body":"## Overview\n\nThe UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.8, UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 2.26.8.26 does not have any capability check in a routine that outputs its stored remote storage settings into admin pages when the site is left in a particular post-migration state, allowing any authenticated user, such as a subscriber, to retrieve the credentials of the configured backup destinations, such as passwords and secret keys.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}