ZeroHour

CVE-2026-19453

moderate

Subscriber-to-Admin Privilege Escalation in JetBackup for WordPress

CVSS 3.1
7.1 high
EPSS
<1%p9
Published
()
Modified
AI analysis

JetBackup for WordPress versions before 3.1.23.5 do not verify the role or capabilities of the account the plugin preserves across a restore or migration before granting it administrator privileges, an improper privilege management flaw (CWE-269). An attacker needs only a subscriber-level account on the target site, and the elevation is triggered when the site owner performs a restore or migration, at which point the low-privilege account is granted administrator access. The attacker then gains full administrative control of the WordPress site, including the ability to modify content and install plugins or themes. Any WordPress site running an affected JetBackup version that has subscriber-level user accounts is affected. No public proof-of-concept or in-the-wild exploitation is known; EPSS estimates a 0.2% probability of exploitation within 30 days and the CVE is not in CISA KEV.

What to do: Update JetBackup for WordPress to 3.1.23.5 or later. Until updated, review and remove or restrict untrusted subscriber-level accounts before running any restore or migration, and defer restores/migrations where possible. After any restore or migration on an affected version, audit the administrators list for unexpected accounts and demote any that were elevated.

Affected
JetApps JetBackup for WordPressbefore 3.1.23.5
Estimated exposure
moderate≈10,000–20,000 active WordPress sites (plugin directory shows on the order of 10,000+ active installs) — The estimate is based on the JetBackup for WordPress plugin's publicly listed active-install count of roughly 10,000+ on the WordPress plugin directory; the number of sites practically exposed is likely lower because exploitation also…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The JetBackup WordPress plugin before 3.1.23.5 does not verify the role or capabilities of the account it preserves across a restore or migration before granting it administrator privileges, allowing a subscriber-level user to gain administrator access after the site owner restores or migrates the site.

Ecosystems
WordPress
Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.