सुरक्षा सलाह पर वापस जाएँ

JetBackup for WordPress CVE-2026-19454: Incorrect Authorization

JetBackup plugin for WordPress is affected by CVE-2026-19454. The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup archives and job logs, allowing an administrator of the network's main site who is. Affected versions: before 3.1.23.5. Fixed in 3.1.23.5. CVSS base score: 4.4.

Medium 4.4 CVSS

प्रभावित संस्करण

before 3.1.23.5

पैच किया गया संस्करण

3.1.23.5

डिफ़ॉल्ट अपडेट कमांड

wp plugin update jetbackup

सुधार कमांड

All supported operating systems

wp plugin update jetbackup
# or: WordPress → Plugins → JetBackup → Update to 3.1.23.5

SharedLicense लाइसेंस के तहत इसका अर्थ

Your SharedLicense license itself is not affected — this is a vulnerability in JetBackup plugin for WordPress (a free WordPress plugin), not in licensing. No license action is needed; update the plugin to protect the sites running on your servers.

The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup archives and job logs, allowing an administrator of the network’s main site who is not a Super Admin to download a full backup of the entire network, including every site’s data and the shared webroot.

Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-19454

अक्सर पूछे जाने वाले प्रश्न

What is CVE-2026-19454?
The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup archives and job logs, allowing an administrator of the network's main site who is. Affected versions: before 3.1.23.5. Fixed in 3.1.23.5.
Is CVE-2026-19454 being exploited in the wild?
No confirmed public exploitation has been announced at the time of writing. With a CVSS base score of 4.4, apply the update on your next maintenance window and watch the vendor advisory for changes.
How do I fix CVE-2026-19454?
wp plugin update jetbackup. or: WordPress → Plugins → JetBackup → Update to 3.1.23.5.
Which versions are affected?
Affected: before 3.1.23.5. Update to 3.1.23.5 or later.

अपने सिस्टम में भेद्यताओं की जाँच करें

अपना उत्पाद और ऑपरेटिंग सिस्टम चुनें ताकि आपके लिए लागू सटीक फिक्स कमांड देख सकें।

अपना सिस्टम जाँचें