{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/keep-backup-daily--2.1.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:keep_backup_daily:keep_backup_daily:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-75133"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Keep Backup Daily (\u003c 2.1.4)"],"_cs_severities":["high"],"_cs_tags":["wordpress","vulnerability","web-application","data-exfiltration"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Keep Backup Daily plugin for WordPress (versions prior to 2.1.4) is vulnerable to a sensitive information exposure flaw. This vulnerability allows an unauthenticated attacker to initiate a full MySQL database dump by invoking the \u003ccode\u003ekbd_cron_process\u003c/code\u003e parameter. The plugin generates backup files in the site's publicly accessible \u003ccode\u003euploads\u003c/code\u003e directory. Because the naming convention for these backup files is partially predictable - based on the database name, a limited randomization factor, and the current Unix timestamp - attackers can enumerate and download these sensitive backups. This exposes the entire site database, including user credentials, configuration secrets, and other sensitive content. This vulnerability is critical for environments where the plugin is enabled, as it provides an automated pathway for total data exfiltration without requiring privileged access.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify WordPress sites running the Keep Backup Daily plugin.\u003c/li\u003e\n\u003cli\u003eAttacker sends an unauthenticated HTTP GET/POST request to the target site using the \u003ccode\u003ekbd_cron_process\u003c/code\u003e parameter to trigger the backup generation script.\u003c/li\u003e\n\u003cli\u003eThe plugin executes the backup routine, dumping the MySQL database into a file within the \u003ccode\u003e/wp-content/uploads/\u003c/code\u003e directory.\u003c/li\u003e\n\u003cli\u003eAttacker monitors the request or estimates the Unix timestamp at the time of execution.\u003c/li\u003e\n\u003cli\u003eAttacker iterates through possible filenames based on the database name and the predictable timestamp and random range.\u003c/li\u003e\n\u003cli\u003eAttacker attempts to download the generated backup file directly via standard web request.\u003c/li\u003e\n\u003cli\u003eAttacker successfully exfiltrates the complete database contents.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to the complete exfiltration of the WordPress database. This includes sensitive data such as site administrator credentials, hashed user passwords, configuration files, and PII of registered users. The breach of this data provides an attacker with the necessary information to perform full account takeover or further compromise the hosting environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch the Keep Backup Daily plugin to version 2.1.4 or later immediately across all WordPress installations.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect attempts to invoke the \u003ccode\u003ekbd_cron_process\u003c/code\u003e parameter from unauthenticated sources.\u003c/li\u003e\n\u003cli\u003eAudit web server logs for suspicious access patterns targeting the \u003ccode\u003e/wp-content/uploads/\u003c/code\u003e directory with file extensions indicative of database backups (e.g., .sql, .zip, .sql.gz).\u003c/li\u003e\n\u003cli\u003eImplement restrictions on the web server to prevent direct access to sensitive file types within the uploads directory.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-31T17:58:26Z","date_published":"2026-08-31T17:58:26Z","id":"https://feed.craftedsignal.io/briefs/2026-08-keep-backup-daily-exposure/","summary":"The Keep Backup Daily plugin for WordPress before 2.1.4 contains a vulnerability allowing unauthenticated attackers to trigger database backups and retrieve them via predictable filenames.","title":"Information Exposure in Keep Backup Daily WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-keep-backup-daily-exposure/"}],"language":"en","title":"CraftedSignal Threat Feed - Keep Backup Daily (\u003c 2.1.4)","version":"https://jsonfeed.org/version/1.1"}