Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2025-15041
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-15041 is a Missing Authorization vulnerability in the BackWPup – WordPress Backup & Restore Plugin that allows authenticated attackers to escalate privileges to administrator level. The flaw affects all versions of the plugin up to and including 5.6.2. It was published on February 19, 2026, and carries a CVSS v3.1 base score of 7.2 (High) (Red Hat CVE, Wordfence).

Technical details

The vulnerability is classified as CWE-862 (Missing Authorization) and stems from the absence of a capability check on the save_site_option() function within the BackWPup plugin. An authenticated attacker with at minimum subscriber-level access can call this function to update arbitrary WordPress site options without proper authorization. By manipulating the default user role for registration to "administrator" and enabling open user registration, an attacker can create a new account with full administrative privileges (Red Hat CVE, Wordfence).

Impact

Successful exploitation grants an attacker full administrative control over the affected WordPress site, resulting in high confidentiality, integrity, and availability impact. An attacker can modify site content, install malicious plugins or themes, exfiltrate stored data (including user credentials and personal information), and potentially use the compromised site as a pivot point for further attacks against site visitors or connected infrastructure (Red Hat CVE).

Exploitability

Exploitation requires an authenticated session with at least subscriber-level access, which limits opportunistic mass exploitation but remains a realistic threat on sites with open registration. The EPSS score is approximately 0.034%, indicating a currently low probability of widespread exploitation. No evidence of active in-the-wild exploitation or inclusion in the CISA KEV catalog has been reported at this time. No public proof-of-concept exploit code has been identified in available sources (Wordfence, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running BackWPup plugin version 5.6.2 or earlier using tools like WPScan or by checking the plugin's readme.txt file at wp-content/plugins/backwpup/readme.txt.
  2. Obtain Authenticated Access: Register or log in to the target WordPress site with any low-privileged account (subscriber level or above). If registration is disabled, this step requires obtaining credentials through other means (e.g., phishing, credential stuffing).
  3. Invoke Vulnerable Function: Send an authenticated HTTP request to the WordPress admin-ajax endpoint or the relevant plugin action that triggers save_site_option(), passing arbitrary option names and values without triggering any capability check.
  4. Enable Open Registration with Admin Role: Set the WordPress option users_can_register to 1 (enabled) and default_role to administrator by crafting appropriate POST parameters in the request.
  5. Register New Admin Account: Navigate to the site's registration page (e.g., /wp-login.php?action=register) and create a new user account, which will automatically be assigned the administrator role.
  6. Achieve Full Site Control: Log in with the newly created administrator account to gain complete control over the WordPress site (Red Hat CVE, Wordfence).

Indicators of compromise

  • Logs: WordPress access logs showing authenticated POST requests to wp-admin/admin-ajax.php or plugin-specific endpoints invoking save_site_option from low-privileged user accounts; unexpected changes to WordPress options logged in the database.
  • Database: Changes to wp_options table entries for users_can_register (set to 1) and default_role (set to administrator) at unexpected times.
  • User Accounts: Newly created WordPress user accounts with the administrator role, especially accounts registered shortly after the option changes above.
  • File System: New or modified plugin/theme files installed by unauthorized administrator accounts following privilege escalation.

Mitigation and workarounds

Users should update the BackWPup plugin to a version beyond 5.6.2 that includes a fix for the missing capability check on save_site_option(). As an interim workaround, site administrators can disable user registration entirely (Settings > General > Membership) and audit existing user accounts for unexpected administrator-level accounts. Reviewing and hardening WordPress user roles and monitoring the wp_options table for unauthorized changes is also recommended (Wordfence, Red Hat CVE).

Community reactions

Wordfence included CVE-2025-15041 in their weekly WordPress vulnerability report for the period of February 16–22, 2026, flagging it as a notable privilege escalation issue in a widely used backup plugin (Wordfence). Security aggregators such as VulDB, Vulners, and RedPacket Security also picked up the advisory shortly after publication, indicating moderate community awareness. No significant vendor statements beyond the CVE disclosure or notable researcher commentary have been identified at this time.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93031HIGH8.8
  • use-your-drive
NoYesSep 18, 2026
CVE-2026-87915HIGH7.2
  • popup-maker
NoYesSep 18, 2026
CVE-2026-18405HIGH7.2
  • jeg-elementor-kit
NoYesSep 18, 2026
CVE-2026-15797MEDIUM6.4
  • popup-maker
NoYesSep 18, 2026
CVE-2026-90884MEDIUM5.4
  • wp-recipe-maker
NoYesSep 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management