{"id":"CVE-2026-16253","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-16253","summary":"The Total Upkeep  WordPress plugin before 1.17.3 does not adequately protect the secret that authorizes its backup-restore functionality and exposes it to unauthenticated users, allowing…","details":"The Total Upkeep  WordPress plugin before 1.17.3 does not adequately protect the secret that authorizes its backup-restore functionality and exposes it to unauthenticated users, allowing them to disclose sensitive backup information and to force a full site restore that overwrites the live site's files and database.","published":"2026-08-12T06:18:55.103","modified":"2026-08-12T06:18:55.103","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://wpscan.com/vulnerability/97abf25a-48d4-4dfa-a7a3-de88455be7eb/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T06:18:55.103"}}