CVE-2026-3339
CVE-2026-3339 describes a limited path traversal vulnerability in the Keep Backup Daily plugin for WordPress, affecting all versions up to 2.1.1. This flaw allows authenticated administrators to list the contents of arbitrary server directories outside the intended uploads folder, due to insufficient validation of the `kbd_path` parameter, resulting in a CVSS score of 2.7 (LOW). There is no evidence of active exploitation, public exploit code, or significant community attention for this vulnerability.
Impacted Technologies
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Fahadmahmood | Keep Backup Daily | >= 0, <= 2.1.1CNA affecteddefault unaffected |
CVSS Data
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Exploit Intelligence
Social Chatter
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
Media Mentions
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation
Remediation records are not available for this CVE.