---
schema: 1
kind: vulnerability
title: "CVE-2026-10795 — UpdraftPlus WordPress backup plugin: unauthenticated authentication bypass to RCE"
headline: "CVE-2026-10795 — UpdraftPlus WordPress backup plugin: unauthenticated authentication bypass to RCE"
summary: "UpdraftPlus WordPress backup plugin (CVE-2026-10795, CVSS 8.1) — unauthenticated auth-bypass to RCE, 3 M+ installs. A failed-RSA-decrypt collapse to an all-zero AES key lets an unauthenticated attacker forge RPC commands and upload a plugin for RCE; Wordfence shipped firewall-rule protection to customers ahead of broad disclosure and the exploitation mechanism is public (WPScan, 2026-06-11). Patch to 1.26.5."
discovered_at: "2026-06-14T05:00:03Z"
event_date: 2026-06-11
run_id: 2026-06-14-e1d80e78
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - auth-bypass
  - rce
  - pre-auth
  - poc-public
  - patch-available
regions:
  - global
sectors:
  - public-sector
entities: []
cves:
  - id: CVE-2026-10795
    cvss: "8.1"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status:
      - poc-public
      - patch-available
sources:
  - url: "https://wpscan.com/vulnerability/68addf8c-9ea6-4b62-9f85-e95350b3992e/"
    publisher: WPScan
    role: primary
  - url: "https://malware.news/t/critical-unauthenticated-authentication-bypass-vulnerability-patched-in-updraftplus-wordpress-plugin/107751"
    publisher: Wordfence via Malware.news
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Update UpdraftPlus to 1.26.5 across all WordPress estates and disable unused UpdraftCentral/Migrator keys (CVE-2026-10795).** Unauthenticated auth-bypass to RCE on 3 M+ installs; the exploitation mechanism is public and Wordfence has shipped preventive rules. Hunt for plugin upload/activation outside change windows and `udrpc_message` POSTs to `admin-ajax.php`."
migrated_from: briefs/2026-06-14.md
---

CVE-2026-10795 (CVSS 8.1) is an unauthenticated authentication bypass in UpdraftPlus: WP Backup & Migration, present in versions ≤ 1.26.4 across an estimated 3 million-plus active installations ([WPScan, 2026-06-11](https://wpscan.com/vulnerability/68addf8c-9ea6-4b62-9f85-e95350b3992e/)). The flaw is in the plugin's remote-communication path: `decrypt_message()` does not validate the return value of `$rsa->decrypt()`, so when RSA decryption fails the resulting `false` is passed to `Rijndael::setKey()` and collapses to a deterministic all-zero AES-128 key — letting an unauthenticated attacker forge RPC commands that execute as the connected administrator, ultimately uploading and activating a malicious plugin for code execution ([Wordfence via Malware.news, 2026-06-11](https://malware.news/t/critical-unauthenticated-authentication-bypass-vulnerability-patched-in-updraftplus-wordpress-plugin/107751)). Exploitation is gated on the site having an active UpdraftCentral or Migrator key configured. Wordfence shipped firewall-rule protection to its customers ahead of broad disclosure and the exploitation mechanism is now public; independent confirmation of in-the-wild exploitation was not located in this run. Fixed in 1.26.5. Hunt for unexpected plugin upload/activation events outside change windows and for `udrpc_message`-bearing POSTs to `admin-ajax.php`; update immediately and disable UpdraftCentral/Migrator keys if unused.
