Vulnerabilities and security researches forpcloud-wp-backup pcloud-wp-backup
Direction: ascendingJul 04, 2026
pCloud WP Backup # CVE-2026-57757
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 02, 2026
- Research Description
- Unauthenticated Cross Site Request Forgery (CSRF) in pCloud WP Backup <= 2.0.2 versions.
- Affected versions
-
max 2.0.2.
- Status
-
vulnerable
Jul 19, 2026
pCloud WP Backup # CVE-2026-14503
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 17, 2026
- Research Description
- The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.3 via the wp2pcl_ajax_process_request_inner. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract force generation of a full-site backup archive written to a publicly accessible directory, exposing wp-config.php database credentials, WordPress secret salts, and the complete PHP source tree. The resulting archive is deposited in the plugin's unprotected tmp/ directory at a predictable URL, making the extracted data accessible to unauthenticated visitors once the backup is triggered.
- Affected versions
-
max 2.0.4.
- Status
-
vulnerable