UpdraftPlus authentication bypass: affected editions and updates | CVE-2026-10795
Check which Updraft product and edition your site uses before choosing an update. The original version of this article incorrectly gave UpdraftCentral the same fixed version as UpdraftPlus. They use different release numbers.
The verified issue
CVE-2026-10795 concerns authentication bypass in UpdraftPlus remote communications. Improper message and signature validation can let an unauthenticated attacker issue commands with the connected administrator’s privileges, potentially leading to remote code execution. NVD reports a CVSS 3.1 score of 8.1 (High). This is not simply a missing WordPress nonce. Read the CVE details.
Use the correct fixed release
| Product | Fixed release identified by the vendor |
|---|---|
| UpdraftPlus Free | 1.26.5 |
| UpdraftPlus Premium | 2.26.5 |
| UpdraftCentral base plugin | 0.8.32 |
These are the fixed releases for this incident, not a claim that they are today’s latest releases. TeamUpdraft says UpdraftCentral Premium did not require this update. Follow its security announcement for the applicable edition and the official hotfix option if an update is temporarily unavailable.
Check the result, not just the update notification
- Record the installed product, edition and version on each affected site.
- Use a trusted update source, then verify that the installed version changed successfully.
- Check for unexpected administrators, plugins and modified files. An update does not remove a compromise that already happened.
- Test a new backup and a restore in an isolated environment. Also test the remote-management connection if your team uses it.
What the original firewall examples could not guarantee
The previous article proposed broad URL keyword blocks as virtual patches. A URL containing “updraft” is not a reliable description of the affected request handler, and blocking all such traffic can interrupt legitimate management. Those untested snippets have been removed. Ask the vendor or your security provider for a rule validated against this specific issue and your integration.
Keep the incident timeline clear
TeamUpdraft’s announcement is dated 5 June 2026; the NVD record was published on 11 June 2026. These are different events. The vendor’s statement about attacks at the time of its announcement should not be presented as a current assessment of exploitation.
Need help reviewing your installation? Use the .