PatchSiren cyber security CVE debrief
CVE-2021-47979 Wordpress CVE debrief
CVE-2021-47979 describes an authenticated arbitrary file deletion issue in the WordPress plugin Backup and Restore 1.0.3. According to the supplied CVE description and NVD data, an attacker can send crafted POST requests to admin-ajax.php and manipulate the file_name and folder_name parameters to delete files from the WordPress installation directory. Because file deletion can damage site availability and potentially remove security-critical files, this issue is high risk for any environment running the affected plugin. The supplied record maps the weakness to CWE-22 and assigns a high severity score (CVSS 8.7).
- Vendor
- Wordpress
- Product
- Unknown
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-16
- Original CVE updated
- 2026-05-18
- Advisory published
- 2026-05-16
- Advisory updated
- 2026-05-18
Who should care
WordPress administrators, site owners, managed hosting providers, and security teams responsible for plugins installed on WordPress sites should care most. Any environment using Backup and Restore 1.0.3 should be treated as potentially affected until it is confirmed removed or updated.
Technical summary
The vulnerability is an authenticated arbitrary file deletion flaw in Backup and Restore 1.0.3 for WordPress. The supplied description states that POST requests to admin-ajax.php can be crafted with attacker-controlled file_name and folder_name parameters to delete arbitrary files within the WordPress installation directory. NVD associates the issue with CWE-22 (path traversal / improper limitation of a pathname to a restricted directory), consistent with file-system boundary abuse.
Defensive priority
High. The impact is immediate and destructive because file deletion can disrupt site availability and may remove configuration or application files. Prioritize any instance of the affected plugin for verification, update, or removal.
Recommended defensive actions
- Verify whether Backup and Restore 1.0.3 is installed on any WordPress instance in your estate.
- If present, remove the plugin or replace it with a version confirmed by the vendor to address the issue.
- Review WordPress and web server logs for suspicious POST requests to admin-ajax.php involving Backup and Restore actions or unusual file_name and folder_name values.
- Check the integrity of the WordPress installation directory and restore any missing or altered files from known-good backups.
- Restrict plugin installation and administration privileges to trusted operators only, and limit exposure of administrative interfaces where feasible.
- Monitor for repeated file-deletion attempts or unexpected filesystem changes after remediation.
Evidence notes
This debrief is based only on the supplied CVE description and NVD source item metadata. The record identifies authenticated arbitrary file deletion in WordPress plugin Backup and Restore 1.0.3, triggered through crafted admin-ajax.php POST requests using file_name and folder_name parameters. The supplied metadata lists CWE-22 and CVSS 4.0 vector data, and the references include the plugin page, a VulnCheck advisory, and NVD/CVE records. No exploit steps beyond the public description are included.
Sources and references
Verified primary and authoritative sources
-
CVE-2021-47979 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2021-47979
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2021-47979 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-47979
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wordpress.org/plugins/backup-and-restore-for-wp/
-
Source reference
Unverified legacy reference
URL: https://www.exploit-db.com/exploits/50503
-
Source reference
Unverified legacy reference
URL: https://www.miniorange.com/
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/wordpress-plugin-backup-and-restore-arbitrary-file-deletion
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.