CVE-2026-19453
moderateSubscriber-to-Admin Privilege Escalation in JetBackup for WordPress
JetBackup for WordPress versions before 3.1.23.5 do not verify the role or capabilities of the account the plugin preserves across a restore or migration before granting it administrator privileges, an improper privilege management flaw (CWE-269). An attacker needs only a subscriber-level account on the target site, and the elevation is triggered when the site owner performs a restore or migration, at which point the low-privilege account is granted administrator access. The attacker then gains full administrative control of the WordPress site, including the ability to modify content and install plugins or themes. Any WordPress site running an affected JetBackup version that has subscriber-level user accounts is affected. No public proof-of-concept or in-the-wild exploitation is known; EPSS estimates a 0.2% probability of exploitation within 30 days and the CVE is not in CISA KEV.
What to do: Update JetBackup for WordPress to 3.1.23.5 or later. Until updated, review and remove or restrict untrusted subscriber-level accounts before running any restore or migration, and defer restores/migrations where possible. After any restore or migration on an affected version, audit the administrators list for unexpected accounts and demote any that were elevated.
| JetApps JetBackup for WordPress | before 3.1.23.5 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The JetBackup WordPress plugin before 3.1.23.5 does not verify the role or capabilities of the account it preserves across a restore or migration before granting it administrator privileges, allowing a subscriber-level user to gain administrator access after the site owner restores or migrates the site.
- Ecosystems
- WordPress
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.