CVE-2026-1311 is a path traversal vulnerability in the Worry Proof Backup plugin for WordPress affecting all versions up to and including 0.2.4. The flaw is in the plugin’s backup upload functionality (noted in upload-backup.php around line 97 per referenced repository links), where a crafted ZIP archive containing path traversal sequences can be uploaded and extracted/handled in a way that allows writing files outside the intended destination directory. An authenticated attacker with Subscriber-level access or higher can leverage this to write arbitrary files anywhere on the server, including placing executable PHP files in web-accessible locations, which can result in remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a standalone Python exploit set for a claimed authenticated path traversal to RCE issue in the Worry Proof Backup WordPress plugin (described as versions <= 0.2.4). It is not part of a larger exploit framework. The repository has three files: a main exploit script (CVE-2026-1311.py), an auxiliary ZIP generator (ADD-CVE-2026-1311.py), and a README with usage examples and sample PHP payloads. The main script is a Python requests-based exploit class that targets a WordPress site, authenticates with low-privilege credentials, and interacts with standard WordPress endpoints such as /wp-login.php, /wp-admin/admin-ajax.php, and /wp-admin/admin-post.php. Based on the visible code and README, its purpose is to upload a crafted ZIP archive to the vulnerable plugin so that path traversal sequences in archive member names cause arbitrary file extraction outside the intended directory. The exploit is designed to place PHP payloads into web-accessible locations such as wp-content, plugins, themes, uploads, wp-admin, wp-includes, or even higher toward the web root. The exploit includes multiple built-in PHP payload templates: a simple command webshell, a stealthier command shell, a reverse shell that connects back to an operator-supplied IP/port, a WordPress administrator creation backdoor, and a phpinfo probe. This indicates post-exploitation capability beyond simple vulnerability verification. The README also claims interactive shell support, file transfer, plugin detection, and multiple traversal techniques, though the provided content is truncated so not every implementation detail is visible. The auxiliary script ADD-CVE-2026-1311.py is a manual payload generator. It creates a malicious ZIP file containing an attacker-supplied PHP file under a traversal path such as ../../../wp-content/webshell.php, plus benign-looking files (backup-info.json and readme.txt) to make the archive appear legitimate. This script supports manual exploitation when the operator wants to upload the ZIP through another channel. Overall, this is an operational authenticated web exploit for WordPress plugin abuse via archive extraction path traversal, with the end goal of arbitrary PHP file write and remote code execution. It is not merely a detector, and it contains actionable payloads rather than just proof-of-concept logic.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.