Critical UpdraftPlus CVE-2026-10795 Exploit Targets Millions
ID: b388fe09-236d-5fac-a566-7c42f755d03b
STIX ID: report--b388fe09-236d-5fac-a566-7c42f755d03b
Feed Name: securityonline.info
A critical authentication-bypass flaw (CVE-2026-10795) in the UpdraftPlus WordPress plugin's UpdraftCentral integration allows unauthenticated attackers to forge encrypted RPC requests, upload malicious plugins, and achieve full site takeover; the issue affects over three million active installations and is being actively attacked (Wordfence reported ~4,987 blocks in 24 hours). The vendor released a patch that fixes the decryption/validation logic, and administrators are strongly urged to update immediately to prevent compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
