CVE-2026-81804
nicheUnauthenticated Sensitive Data Exposure in ZHBackup WordPress Plugin
CVE-2026-81804 is an unauthenticated sensitive data exposure flaw (CWE-201) in the ZHBackup – Backup, Restore & Migration plugin for WordPress, affecting all versions up to and including 2.4.2. Because the vulnerable functionality requires no privileges, any remote attacker can trigger it simply by sending unauthenticated requests to the affected plugin endpoint, with no account, credentials, or user interaction needed. Successful abuse results in disclosure of sensitive information handled by the plugin — which, for a backup and migration tool, may include site or backup-related data — with a high confidentiality impact only and no effect on integrity or availability per the CVSS vector. Any WordPress site running ZHBackup version 2.4.2 or earlier is affected. There is no public proof-of-concept, the flaw is not listed in CISA's KEV catalog, and no exploitation in the wild has been confirmed.
What to do: Update ZHBackup to the first release newer than 2.4.2 as soon as a patched version is published (check the WordPress plugin directory or the vendor's changelog; no fixed version number is specified in the disclosure data). Until patched, restrict unauthenticated access to the plugin's routes/endpoints where possible and review whether any generated backups or exposed data could have been retrieved. Continue monitoring the plugin page for the security release.
| ZHBackup – Backup, Restore & Migration (WordPress plugin) | <= 2.4.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore & Migration <= 2.4.2 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-201
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.