CVE-2026-18386 | cssimmon WP BackItUp Community Edition Plugin up to 2.1.0 on WordPress basename backup_file path traversal

SecurityVulns

A vulnerability classified as problematic was found in cssimmon WP BackItUp Community Edition Plugin up to 2.1.0 on WordPress. Affected by this vulnerability is the function basename. The manipulation of the argument backup_file results in path traversal.

This vulnerability is known as CVE-2026-18386. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More