ZeroHour

CVE-2026-81804

niche

Unauthenticated Sensitive Data Exposure in ZHBackup WordPress Plugin

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-81804 is an unauthenticated sensitive data exposure flaw (CWE-201) in the ZHBackup – Backup, Restore & Migration plugin for WordPress, affecting all versions up to and including 2.4.2. Because the vulnerable functionality requires no privileges, any remote attacker can trigger it simply by sending unauthenticated requests to the affected plugin endpoint, with no account, credentials, or user interaction needed. Successful abuse results in disclosure of sensitive information handled by the plugin — which, for a backup and migration tool, may include site or backup-related data — with a high confidentiality impact only and no effect on integrity or availability per the CVSS vector. Any WordPress site running ZHBackup version 2.4.2 or earlier is affected. There is no public proof-of-concept, the flaw is not listed in CISA's KEV catalog, and no exploitation in the wild has been confirmed.

What to do: Update ZHBackup to the first release newer than 2.4.2 as soon as a patched version is published (check the WordPress plugin directory or the vendor's changelog; no fixed version number is specified in the disclosure data). Until patched, restrict unauthenticated access to the plugin's routes/endpoints where possible and review whether any generated backups or exposed data could have been retrieved. Continue monitoring the plugin page for the security release.

Affected
ZHBackup – Backup, Restore & Migration (WordPress plugin)<= 2.4.2
Estimated exposure
nichelikely well under 10,000 sites (estimate; no published active-install count for this niche plugin was included in the disclosure data) — No active-install figure for the ZHBackup plugin was provided or is widely published, so the estimate relies on typical deployment patterns of low-profile WordPress backup plugins, which are generally installed on hundreds to low thousands…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore & Migration <= 2.4.2 versions.

Ecosystems
WordPress
Weakness
CWE-201
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.