
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-15041 is a Missing Authorization vulnerability in the BackWPup – WordPress Backup & Restore Plugin that allows authenticated attackers to escalate privileges to administrator level. The flaw affects all versions of the plugin up to and including 5.6.2. It was published on February 19, 2026, and carries a CVSS v3.1 base score of 7.2 (High) (Red Hat CVE, Wordfence).
The vulnerability is classified as CWE-862 (Missing Authorization) and stems from the absence of a capability check on the save_site_option() function within the BackWPup plugin. An authenticated attacker with at minimum subscriber-level access can call this function to update arbitrary WordPress site options without proper authorization. By manipulating the default user role for registration to "administrator" and enabling open user registration, an attacker can create a new account with full administrative privileges (Red Hat CVE, Wordfence).
Successful exploitation grants an attacker full administrative control over the affected WordPress site, resulting in high confidentiality, integrity, and availability impact. An attacker can modify site content, install malicious plugins or themes, exfiltrate stored data (including user credentials and personal information), and potentially use the compromised site as a pivot point for further attacks against site visitors or connected infrastructure (Red Hat CVE).
Exploitation requires an authenticated session with at least subscriber-level access, which limits opportunistic mass exploitation but remains a realistic threat on sites with open registration. The EPSS score is approximately 0.034%, indicating a currently low probability of widespread exploitation. No evidence of active in-the-wild exploitation or inclusion in the CISA KEV catalog has been reported at this time. No public proof-of-concept exploit code has been identified in available sources (Wordfence, Red Hat CVE).
wp-content/plugins/backwpup/readme.txt.save_site_option(), passing arbitrary option names and values without triggering any capability check.users_can_register to 1 (enabled) and default_role to administrator by crafting appropriate POST parameters in the request./wp-login.php?action=register) and create a new user account, which will automatically be assigned the administrator role.wp-admin/admin-ajax.php or plugin-specific endpoints invoking save_site_option from low-privileged user accounts; unexpected changes to WordPress options logged in the database.wp_options table entries for users_can_register (set to 1) and default_role (set to administrator) at unexpected times.administrator role, especially accounts registered shortly after the option changes above.Users should update the BackWPup plugin to a version beyond 5.6.2 that includes a fix for the missing capability check on save_site_option(). As an interim workaround, site administrators can disable user registration entirely (Settings > General > Membership) and audit existing user accounts for unexpected administrator-level accounts. Reviewing and hardening WordPress user roles and monitoring the wp_options table for unauthorized changes is also recommended (Wordfence, Red Hat CVE).
Wordfence included CVE-2025-15041 in their weekly WordPress vulnerability report for the period of February 16–22, 2026, flagging it as a notable privilege escalation issue in a widely used backup plugin (Wordfence). Security aggregators such as VulDB, Vulners, and RedPacket Security also picked up the advisory shortly after publication, indicating moderate community awareness. No significant vendor statements beyond the CVE disclosure or notable researcher commentary have been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."