Attack attempts have been detected that seek to distribute a malicious PHP backdoor by exploiting the CVE-2026-10795 vulnerability in the UpdraftPlus product.
This vulnerability is an authentication bypass vulnerability that occurred during the validation of remote communication messages in the UpdraftPlus plugin, caused by inadequate verification of encrypted signatures.
Affected versions include UpdraftPlus: WP Backup & Migration Plugin version 1.26.4 Or earlier and UpdraftPlus Premium version 2.26.5 Or earlier.
This vulnerability has been rated CVSS 9.8, Indicating a very high severity.
A patch has been provided via the latest update; users must update to UpdraftPlus: WP Backup & Migration Plugin version 1.26.5 Or later or UpdraftPlus Premium version 2.26.5 Or later.