CVE-2026-1311

HIGH

Worry Proof Backup Plugin <0.2.4 - Path Traversal

Title source: llm

Description

The Worry Proof Backup plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.2.4 via the backup upload functionality. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload a malicious ZIP archive with path traversal sequences to write arbitrary files anywhere on the server, including executable PHP files. This can lead to remote code execution.

Exploits (2)

github WORKING POC 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-1311
nomisec WORKING POC
by hacker1337itme · poc
https://github.com/hacker1337itme/CVE-2026-1311

Scores

CVSS v3 8.8
EPSS 0.0012
EPSS Percentile 31.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-22
Status published
Products (1)
bearsthemes/Worry Proof Backup < 0.2.4
Published Feb 26, 2026
Tracked Since Feb 26, 2026