CVE detail
CVE-2026-14503
The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.3 via the wp2pcl_ajax_process_request_inner. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract force generation of a full-site backup archive written to a publicly accessible directory, exposing wp-config.php database credentials, WordPress secret salts, and the complete PHP source tree. The resulting archive is deposited in the plugin's unprotected tmp/ directory at a predictable URL, making the extracted data accessible to unauthenticated visitors once the backup is triggered.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 8
- within the 30d window
- Peak daily
- 7
- highest bucket
Evidence
Source links by recency
8 source links · newest first
- Wordfence Intelligence Weekly WordPress Vulnerability Report (July 13, 2026 to July 19, 2026)Wordfence
re 6.9 - 7.0.1 - Remote Code Execution via REST API Batch Request Route Confusion 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-63030 Patch Status Patched Published Jul 17, 2026 Affected Software WordPress [wordpress] Researcher Adam Kues More Details > Digits: WordPress Mobile Number Signup and Login Loco Translate Paid Membership Plugin, Ecommerce,
vendorwww.wordfence.comJul 23, 2026, 8:42 PM - https://www.wordfence.com/threat-intel/vulnerabilities/id/0b301c6e-a3c5-4435-9bc9-fab18085fe2d?source=cvewww.wordfence.com
No excerpt available.
Patchwww.wordfence.comJul 17, 2026, 5:16 AM - https://plugins.trac.wordpress.org/changeset?reponame=&old=3597399%40pcloud-wp-backup&new=3597399%40pcloud-wp-backupplugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 17, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/pcloud-wp-backup/tags/2.0.2/pcloud-wp-backup.php#L572plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 17, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/pcloud-wp-backup/tags/2.0.2/pcloud-wp-backup.php#L217plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 17, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/pcloud-wp-backup/tags/2.0.2/pcloud-wp-backup.php#L210plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 17, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/pcloud-wp-backup/tags/2.0.2/pcloud-wp-backup.php#L1635plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 17, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/pcloud-wp-backup/tags/2.0.2/Pcloud/Classes/class-wp2pcloudfilebackup.php#L111plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 17, 2026, 5:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-17457CVSS 2.1 · Low
A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by this issue is the function assertBrowserNavigationAllowed of the file src/browser/navigation-guard.t…
- CVE-2026-55729CVSS 7.7 · High
Exposure of Sensitive Information (CWE-200) in LWEB802 browser `localStorage` in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to leak st…
- CVE-2026-17048CVSS 5.5 · Medium
A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secret…
- CVE-2026-49159CVSS 6.5 · Medium
Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.
- CVE-2026-47743CVSS 8.7 · High
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed data tampering, sensitive data disclosure, and stored XSS.…
- CVE-2026-65760CVSS 9.2 · Critical
Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to…