Skip to main content
Mallory
Back to intelligence
actively-exploited-vulnerabilityinternet-facing-service-vulnerabilitywidely-deployed-product-advisoryrapid-weaponization

Active Exploitation of UpdraftPlus Auth Bypass Enables WordPress Site Takeover

Updated 24h agoFirst seen Jun 11, 20264 sources

A critical authentication bypass in the UpdraftPlus: WP Backup & Migration WordPress plugin, tracked as CVE-2026-10795, is being actively exploited against sites running versions up to and including 1.26.4. The flaw affects a plugin installed on more than three million WordPress sites and stems from insufficient validation in UpdraftCentral remote procedure call handling, including signature-verification weaknesses and unchecked decryption return values that can collapse to a predictable all-zero key. Wordfence reported blocking 4,987 exploitation attempts in a 24-hour period.

Successful exploitation lets unauthenticated attackers impersonate the connected administrator and issue arbitrary RPC actions, including uploading and auto-activating a malicious plugin for remote code execution and full site compromise. The vulnerability has been classified under CWE-347, with a CVSS v3.1 vector of AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. The issue was reportedly discovered by researcher vtim, and the vendor released a patch that adds stricter return-value validation; administrators are being urged to update immediately.

Share:
Active Exploitation of UpdraftPlus Auth Bypass Enables WordPress Site Takeover
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Jun 17, 20262d ago

Nuclei template updated to reduce CVE-2026-10795 false positives

A ProjectDiscovery pull request updated the Nuclei detection template for CVE-2026-10795 after the original logic falsely flagged non-WordPress applications such as Zimbra. The revised matcher now looks for the JSON key pattern "\"udrpc_message\":\"" to better match vulnerable UpdraftPlus responses, while patched 1.26.5 instances should no longer match.

Fix false positive in CVE-2026-10795 (UpdraftPlus UpdraftCentral auth bypass) by Eren-Akdag · Pull Request #16418 · projectdiscovery/nuclei-templates · GitHub
Jun 11, 20268d ago

CVE-2026-10795 is received by Wordfence

The CVE record states that security@wordfence.com received vulnerability CVE-2026-10795 on this date. The flaw was categorized as CWE-347 and described as an authentication bypass leading to possible remote code execution.

CVE-2026-10795 - UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication Bypass via UpdraftCentral udrpc
Jun 10, 20268d ago

Wordfence observes active exploitation of UpdraftPlus flaw

Wordfence reported active exploitation of CVE-2026-10795 and said it blocked 4,987 attack attempts within a 24-hour period. Successful exploitation can lead to malicious plugin upload, activation, and full site compromise.

UpdraftPlus CVE-2026-10795: 3M Sites Actively Exploited

UpdraftPlus releases patch for CVE-2026-10795

The UpdraftPlus development team released a fix for CVE-2026-10795 by adding a strict return-value check. The issue affects plugin versions up to and including 1.26.4.

UpdraftPlus CVE-2026-10795: 3M Sites Actively Exploited

Researcher discovers UpdraftPlus authentication bypass flaw

The UpdraftPlus vulnerability CVE-2026-10795 was reportedly discovered by researcher vtim, who received a $5,200 bounty for responsible disclosure. The flaw affects UpdraftCentral RPC handling and can let unauthenticated attackers act as the connected administrator.

UpdraftPlus CVE-2026-10795: 3M Sites Actively Exploited
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

11 LINKEDOpen in app
Affected products
3 linked
WordpressUpdraftplusWordfence
Organizations
6 linked
UpdraftplusWordfenceZimbraPatchstackSecurityOnline.infoTheme Spirit
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Active Exploitation of UpdraftPlus Auth Bypass Enables WordPress Site Takeover | Mallory