CVE-2026-1311
HIGHWorry Proof Backup Plugin <0.2.4 - Path Traversal
Title source: llmDescription
The Worry Proof Backup plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.2.4 via the backup upload functionality. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload a malicious ZIP archive with path traversal sequences to write arbitrary files anywhere on the server, including executable PHP files. This can lead to remote code execution.
Exploits (2)
github
WORKING POC
10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-1311
References (3)
Scores
CVSS v3
8.8
EPSS
0.0012
EPSS Percentile
31.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-22
Status
published
Products (1)
bearsthemes/Worry Proof Backup
< 0.2.4
Published
Feb 26, 2026
Tracked Since
Feb 26, 2026