CVE-2026-76549
The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one of its backup management actio
CVSS
5.9
Medium
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 27, 2026 · Last modified: Aug 27, 2026 · CWE-352
Not enough EPSS history yet.
The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one of its backup management actions, which could allow attackers to make a logged in admin restore an existing backup, reverting the site's database and files to an earlier state, via a crafted link.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-802106.5 MED—
———FrontAccounting through 2.4.20 generates a CSRF token in end_form() in includes/ui/ui_controls.inc and embeds it as the _token hidden field in every form it renders, but only admin/users.php and admin/change_current_user_password.php call check_csrf_token() to validate it. No financial transaction handler validates the token, including gl/gl_journal.php, gl/gl_bank.php, purchasing/supplier_invoice.php, sales/customer_invoice.php, sales/customer_payments.php and admin/company_preferences.php, so those endpoints act on POST data with no origin check. An attacker who gets an authenticated user to load a page under attacker control can auto-submit a cross-origin form to any of them and have the forged journal entry, invoice, customer payment, bank transaction or company configuration change recorded under the victim's session.5hCVE-2026-812738.1 HIG—
———Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.8hCVE-2026-812718.8 HIG—
———Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.8hCVE-2025-567988.8 HIG—
———Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier allows remote attackers to escalate privileges via the Unraid authentication cookie's lax same-site policy.5hCVE-2026-485486.5 MED—
———Nagios Core before 4.5.12 contains a cross-site request forgery vulnerability in cmd.cgi where the CSRF protection mechanism passes validation when the NagFormId cookie is absent. Attackers can craft a malicious cross-site POST request to execute arbitrary Nagios commands as a currently authenticated user without their knowledge or consent.1dCVE-2026-782804.3 MED0.8%
——0Unauthenticated Cross Site Request Forgery (CSRF) in Hash Form <= 1.4.0 versions.3d