---
id: CVE-2026-82841
title: >-
  The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.8,
  UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 2.26.8.26
  does not have any capability check in a routine that outputs its stored remote
  stor…
summary: >-
  The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.8,
  UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 2.26.8.26
  does not have any capability check in a routine that outputs its stored remote
  stor…
severity: none
cwe:
  - CWE-200
product: 'UpdraftPlus: WP Backup & Migration Plugin'
affected:
  - updraftplus_wp_backup_migration_plugin >= 1.23.8 < 1.26.8
  - updraftplus_wp_backup_migration_plugin >= 2.23.8 < 2.26.8.26
published: '2026-09-27'
updated: '2026-09-27'
sourceUpdated: '2026-09-27T06:17:03.433'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82841'
references:
  - url: 'https://wpscan.com/vulnerability/52f39a82-89ee-43f1-ba9c-3ea646fb0a0e/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-27T06:43:46.828Z'
---

## Overview

The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.8, UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 2.26.8.26 does not have any capability check in a routine that outputs its stored remote storage settings into admin pages when the site is left in a particular post-migration state, allowing any authenticated user, such as a subscriber, to retrieve the credentials of the configured backup destinations, such as passwords and secret keys.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
