The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, including the database with user password hashes, and to delete arbitrary files on the server, leading to sensitive data disclosure and site takeover. The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 has been closed on WordPress.org since July 2024 and no fixed version is available. Remove it from any site where it is installed.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
The BackupSheep WordPress Backup Plugin through version 1.8 contains a critical authentication bypass vulnerability (CWE-73: External Control of File Name or Path) where unset or blank integration keys are treated as valid. This allows unauthenticated attackers to interact with the plugin's backup functionality without proper authorization. Attackers can create and download complete site backups containing databases with user password hashes, and delete arbitrary files from the server. Any WordPress installation using this vulnerable plugin version is exposed to sensitive data disclosure, lateral movement opportunities via compromised credentials, and complete site takeover through file deletion attacks. This affects all users of the plugin until they upgrade beyond version 1.8.
While this CVE currently maps to zero Casky skills due to its plugin-specific nature, a practitioner would detect exploitation patterns through behavioral analysis: unauthorized backup creation and download requests from non-admin IPs, particularly requests lacking proper authentication headers or containing blank/null credential values in API integrations. Extended reasoning across security logs would reveal file system modifications (deletions) correlating with backup API calls, and database access patterns inconsistent with legitimate backup operations. Detection would focus on monitoring WordPress backup plugin endpoints for missing authentication validation, tracking unauthenticated requests to backup creation functions, and correlating sudden credential exposure (password hash dumps) with backup plugin activity. Organizations should implement Web Application Firewall rules to block unauthenticated access to backup endpoints and audit backup plugin configurations to ensure integration keys are properly enforced.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-101148. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation