---
id: CVE-2026-101148
title: >-
  The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not
  properly validate its integration key, treating an unset or blank key as
  valid, which allows unauthenticated attackers to create and download full site
  backups…
summary: >-
  The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not
  properly validate its integration key, treating an unset or blank key as
  valid, which allows unauthenticated attackers to create and download full site
  backups…
severity: critical
cvss: 10
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-73
product: BackupSheep WordPress Backup Plugin
affected:
  - backupsheep_wordpress_backup_plugin <= 1.8
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T13:11:52.923'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-101148'
references:
  - url: 'https://wpscan.com/vulnerability/5d6fce13-34e3-4ec6-9b47-a78dd7c94fed/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-10-01T10:45:06.105846Z'
ingestedAt: '2026-10-01T06:38:44.645Z'
---

## Overview

The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, including the database with user password hashes, and to delete arbitrary files on the server, leading to sensitive data disclosure and site takeover.

The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 has been closed on WordPress.org since July 2024 and no fixed version is available. Remove it from any site where it is installed.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
