What is CVE-2026-16253?
The Total Upkeep WordPress plugin before version 1.17.3 fails to properly protect the secret key used for its backup-restore functionality, exposing it to unauthenticated users. This vulnerability allows attackers to disclose sensitive backup information and force a full site restore that overwrites the live site's files. Users should immediately update the plugin to the latest version.
Azərbaycanca: Total Upkeep WordPress plaqini 1.17.3 versiyasından əvvəl ehtiyat nüsxə funksiyası üçün istifadə olunan gizli açarı qeyri-adekvat qoruyur. Bu zəiflik autentifikasiya olunmamış istifadəçilərə həssas ehtiyat nüsxə məlumatlarını ifşa etməyə və canlı saytın fayllarını üzərindən yazaraq tam sayt bərpasına məcbur etməyə imkan verir. İstifadəçilər dərhal plaqini ən son versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
What risk does the CVE-2026-16253 vulnerability in the Total Upkeep plugin pose?
This vulnerability allows unauthenticated users to disclose sensitive backup information and force a full site restore that overwrites the live site's files.
How can users protect against the CVE-2026-16253 vulnerability?
Users should immediately update the Total Upkeep plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.