JetBackup for WordPress CVE-2026-19454: Incorrect Authorization
JetBackup plugin for WordPress is affected by CVE-2026-19454. The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup archives and job logs, allowing an administrator of the network's main site who is. Affected versions: before 3.1.23.5. Fixed in 3.1.23.5. CVSS base score: 4.4.
Затронутые версии
before 3.1.23.5
Исправленная версия
3.1.23.5
Команда обновления по умолчанию
wp plugin update jetbackup
Команды исправления
All supported operating systems
wp plugin update jetbackup
# or: WordPress → Plugins → JetBackup → Update to 3.1.23.5
Что это значит по лицензии SharedLicense
Your SharedLicense license itself is not affected — this is a vulnerability in JetBackup plugin for WordPress (a free WordPress plugin), not in licensing. No license action is needed; update the plugin to protect the sites running on your servers.
The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup archives and job logs, allowing an administrator of the network’s main site who is not a Super Admin to download a full backup of the entire network, including every site’s data and the shared webroot.
Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-19454
Часто задаваемые вопросы
What is CVE-2026-19454?
Is CVE-2026-19454 being exploited in the wild?
How do I fix CVE-2026-19454?
Which versions are affected?
Источники
Проверьте систему на уязвимости
Выберите продукт и операционную систему, чтобы увидеть точные команды исправления.
Проверьте свою систему