If your website uses the UpdraftPlus backup plugin, here is the short version: a critical vulnerability was discovered in the plugin, and we have already updated it to the patched version on all affected sites we host. You are protected, and there is nothing you need to do.
Below is what happened, what we did, and what to keep an eye on.
Your site is already protected
On June 11, 2026, our engineering team force-updated the UpdraftPlus plugin across all hosted sites running a vulnerable version. Every affected installation was moved to version 1.26.5, which contains the official fix. More than 128 000 sites on our platform were running a vulnerable version, and all of them have been patched.
We tested the upgrade paths before rolling anything out and found no issues. We do not expect any site breakages as a result of this update.
What the vulnerability is
The flaw, tracked as CVE-2026-10795, is an Unauthenticated Authentication Bypass affecting UpdraftPlus versions up to 1.26.4. In plain terms, it allowed attackers to gain administrator access to a WordPress site without knowing any username or password. From there, they could execute code on the site, which is about as serious as a plugin vulnerability gets.
The “unauthenticated” part is what makes this critical. Many vulnerabilities require an attacker to already have some level of access, like a subscriber or contributor account. This one required nothing at all. Any site running a vulnerable version was exposed to anyone who knew about the flaw.
What we did and when
As soon as the vulnerability was disclosed, it took our team less than an hour to proactively complete the update of the patched version of the plugin to all affected sites, acting immediately to close the exposure window before attackers could exploit it at scale, rather than waiting for site owners to update manually, or be affected in any way.
Here is what the response looked like:
- We identified all hosted sites running UpdraftPlus versions 1.24.x, 1.25.x and 1.26.x.
- We tested upgrades from 1.24.x to 1.26.x and other affected versions to 1.26.5 in advance to confirm the update would not cause problems.
- We force-updated more than 128 000 affected installations to the patched version 1.26.5.
- The whole process was complete in ~52 mins.
Will the update affect my website?
We do not expect it to. Plugin updates between these versions were tested before the rollout, and no issues came up.
That said, if you want extra peace of mind, here are two quick things you can check:
- Confirm your backup schedule in UpdraftPlus is still configured the way you set it.
- Verify that your most recent backup completed successfully.
Both take less than a minute from your WordPress dashboard.
Why we force updates for critical vulnerabilities
When a vulnerability is critical, trivially exploitable, and publicly disclosed, every hour of delay matters. Attackers begin scanning for vulnerable sites within hours of a disclosure like this one, and waiting for each site owner to update manually would leave thousands of sites exposed in the meantime.
In those situations, we patch first and notify right after. We believe a proactive update is always the better trade compared to leaving sites open to full takeover.
As a general rule, we also recommend keeping plugin auto-updates enabled wherever possible. It is the single most effective habit for staying ahead of vulnerabilities like this one.

