UpdraftPlus Security Update Recommendation

UpdraftPlus Security Update Recommendation
  • Attack attempts have been detected that seek to distribute a malicious PHP backdoor by exploiting the CVE-2026-10795 vulnerability in the UpdraftPlus product.
  • This vulnerability is an authentication bypass vulnerability that occurred during the validation of remote communication messages in the UpdraftPlus plugin, caused by inadequate verification of encrypted signatures.
  • Affected versions include UpdraftPlus: WP Backup & Migration Plugin version 1.26.4 Or earlier and UpdraftPlus Premium version 2.26.5 Or earlier.
  • This vulnerability has been rated CVSS 9.8, Indicating a very high severity.
  • A patch has been provided via the latest update; users must update to UpdraftPlus: WP Backup & Migration Plugin version 1.26.5 Or later or UpdraftPlus Premium version 2.26.5 Or later.