UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 (free) < 2.26.5 (premium) - Unauthenticated Authentication Bypass via UpdraftCentral udrpc
critical
The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.4 (free) and versions up to 2.26.5 (premium) via the UpdraftPlus_Remote_Communications_V2::wp_loaded function. This is due to insufficient validation of the remote communi...
- CVSS:
- 9.8
- Affected:
- 2.0 – 2.26.5
- Fixed in:
- 2.26.5
- Disclosed:
- Jun 10, 2026
CVE-2026-10795 on NVD →
UpdraftPlus - Backup/Restore <= 1.24.12 - Reflected Cross-Site Scripting
medium
The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the showdata and initiate_restore parameters in all versions up to, and including, 1.24.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attacke...
- CVSS:
- 6.1
- Affected:
- up to 1.24.12
- Fixed in:
- 1.25.1
- Disclosed:
- Jan 15, 2025
CVE-2025-0215 on NVD →
UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.24.12
unknown
[en] The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions from 1.23.8 to 1.24.11 via deserialization of untrusted input in the 'recursive_unserialized_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No kn...
- Affected:
- up to 1.24.12
- Fixed in:
- 1.24.12
- Disclosed:
- Jan 4, 2025
CVE-2024-10957 on NVD →
UpdraftPlus: WP Backup & Migration Plugin 1.23.8 - 1.24.11 - Unauthenticated PHP Object Injection
high
The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions from 1.23.8 to 1.24.11 via deserialization of untrusted input in the 'recursive_unserialized_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known P...
- CVSS:
- 8.8
- Affected:
- 1.23.8 – 1.24.11
- Fixed in:
- 1.24.12
- Disclosed:
- Jan 3, 2025
CVE-2024-10957 on NVD →
UpdraftPlus <= 1.23.10 - Cross-Site Request Forgery to Google Drive Storage Update
medium
The UpdraftPlus: WordPress Backup & Migration Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.23.10. This is due to a lack of nonce validation and insufficient validation of the instance_id on the 'updraftmethod-googledrive-auth' action used to update Goog...
- CVSS:
- 5.4
- Affected:
- up to 1.23.10
- Fixed in:
- 1.23.11
- Disclosed:
- Nov 7, 2023
CVE-2023-5982 on NVD →
UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.23.11
unknown
[en] The UpdraftPlus: WordPress Backup & Migration Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.23.10. This is due to a lack of nonce validation and insufficient validation of the instance_id on the 'updraftmethod-googledrive-auth' action used to update...
- Affected:
- up to 1.23.11
- Fixed in:
- 1.23.11
- Disclosed:
- Nov 7, 2023
CVE-2023-5982 on NVD →
UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.23.4
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in UpdraftPlus.Com, DavidAnderson UpdraftPlus WordPress Backup Plugin <= 1.23.3 versions leads to sitewide Cross-Site Scripting (XSS).
- Affected:
- up to 1.23.4
- Fixed in:
- 1.23.4
- Disclosed:
- Jun 22, 2023
CVE-2023-32960 on NVD →
UpdraftPlus <= 1.23.3 - Cross-Site Request Forgery to Cross-Site Scripting via action_authenticate_storage
medium
The UpdraftPlus plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.23.3. This is due to missing or incorrect nonce validation on the action_authenticate_storage function. This makes it possible for unauthenticated attackers to inject JavaScript into a parameter in the a...
- CVSS:
- 6.1
- Affected:
- up to 1.23.3
- Fixed in:
- 1.23.4
- Disclosed:
- May 18, 2023
CVE-2023-32960 on NVD →
UpdraftPlus 1.22.14 to 1.23.2 and UpdraftPlus (Premium) 2.22.14 to 2.23.2 - Privilege Escalation via updraft_central_ajax_handler
high
The UpdraftPlus plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the 'updraft_central_ajax_handler' function in versions from 1.22.14 to 1.23.2 inclusive, and 2.22.14 to 2.23.2 of the premium version. This allows authenticated attackers, with subscriber-level permissions or abo...
- CVSS:
- 8.8
- Affected:
- 1.22.14 – 1.23.2, 2.22.14 – 2.23.2
- Fixed in:
- 1.23.3
- Disclosed:
- Mar 16, 2023
UpdraftPlus: WP Backup & Migration Plugin [updraftplus] >= 1.22.14 - <= 1.23.2
unknown
Update the WordPress UpdraftPlus plugin to the latest available version (at least 1.23.3).
An unknown person discovered and reported this Broken Access Control vulnerability in WordPress UpdraftPlus Plugin. This vulnerability has been fixed in version 1.23.3.
- Affected:
- 1.22.14 – 1.23.2
- Fixed in:
- 1.23.2
- Disclosed:
- Mar 16, 2023
UpdraftPlus: WP Backup & Migration Plugin [updraftplus] >= 2.22.14 - <= 2.23.2
unknown
Update the WordPress UpdraftPlus PRO plugin to the latest available version (at least 2.23.3).
An unknown person discovered and reported this Broken Access Control vulnerability in WordPress UpdraftPlus Plugin. This vulnerability has been fixed in version 2.23.3.
- Affected:
- 2.22.14 – 2.23.2
- Fixed in:
- 2.23.2
- Disclosed:
- Mar 16, 2023
UpdraftPlus: WP Backup & Migration Plugin [updraftplus] >= 1.22.14 - <= 1.23.2
unknown
The UpdraftPlus plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the 'updraft_central_ajax_handler' function in versions from 1.22.14 to 1.23.2 inclusive, and 2.22.14 to 2.23.2 of the premium version. This allows authenticated attackers, with subscriber-level permissions or abo...
- Affected:
- 1.22.14 – 1.23.2
- Fixed in:
- 1.23.2
- Disclosed:
- Mar 16, 2023
UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.23.1
unknown
Update the WordPress UpdraftPlus Extension plugin to the latest available version (at least 1.23.1).
Unknown discovered and reported this Sensitive Data Exposure vulnerability in WordPress UpdraftPlus Plugin. This vulnerability has been fixed in version 1.23.1.
- Affected:
- up to 1.23.1
- Fixed in:
- 1.23.1
- Disclosed:
- Mar 9, 2023
UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.23.1
unknown
Update the WordPress MainWP UpdraftPlus Extension plugin to the latest available version (at least 1.23.1).
Unknown discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress UpdraftPlus Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted action...
- Affected:
- up to 1.23.1
- Fixed in:
- 1.23.1
- Disclosed:
- Mar 9, 2023
Updraft Plus <= 1.22.24 - Information Disclosure via updraft_ajaxrestore
medium
The Updraft Plus plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 1.22.24. This is due to the fact that the 'updraft_ajaxrestore' function generates a log file containing system configuration information. This makes it possible for unauthenticated attackers to trigger gener...
- CVSS:
- 5.3
- Affected:
- up to 1.22.24
- Fixed in:
- 1.23.1
- Disclosed:
- Mar 8, 2023
UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.23.1
unknown
The Updraft Plus plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 1.22.24. This is due to the fact that the 'updraft_ajaxrestore' function generates a log file containing system configuration information. This makes it possible for unauthenticated attackers to trigger gener...
- Affected:
- up to 1.23.1
- Fixed in:
- 1.23.1
- Disclosed:
- Mar 8, 2023
UpdraftPlus WordPress Backup Plugin < 1.22.9 Reflected Cross-Site Scripting
medium
The "UpdraftPlus WordPress Backup Plugin" plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'updraft_interval' parameter in versions up to 1.22.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...
- CVSS:
- 6.1
- Affected:
- up to 1.22.9
- Fixed in:
- 1.22.9
- Disclosed:
- Apr 7, 2022
CVE-2022-0864 on NVD →
UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.22.9
unknown
[en] The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.
- Affected:
- up to 1.22.9
- Fixed in:
- 1.22.9
- Disclosed:
- Apr 4, 2022
CVE-2022-0864 on NVD →
UpdraftPlus WordPress Backup Plugin < 1.22.3 - Sensitive Information Disclosure
medium
The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download the most recent site & database backup.
The UpdraftPl...
- CVSS:
- 6.5
- Affected:
- 1.16.7 – 1.22.3
- Fixed in:
- 1.22.3
- Disclosed:
- Feb 17, 2022
CVE-2022-0633 on NVD →
UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.22.3
unknown
[en] The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download the most recent site & database backup.
- Affected:
- up to 1.22.3
- Fixed in:
- 1.22.3
- Disclosed:
- Feb 17, 2022
CVE-2022-0633 on NVD →
UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.16.69
unknown
[en] The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.69 does not sanitise and escape the updraft_restore parameter before outputting it back in the Restore page, leading to a Reflected Cross-Site Scripting
- Affected:
- up to 1.16.69
- Fixed in:
- 1.16.69
- Disclosed:
- Feb 1, 2022
CVE-2021-25089 on NVD →
UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.6.59
unknown
[en] The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft_service settings, allowing high privilege users to set malicious JavaScript payload in it and leading to a Stored Cross-Site Scripting issue
- Affected:
- up to 1.6.59
- Fixed in:
- 1.6.59
- Disclosed:
- Jan 24, 2022
CVE-2021-24423 on NVD →
UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.16.66
unknown
[en] The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.66 does not sanitise and escape the backup_timestamp and job_id parameter before outputting then back in admin pages, leading to Reflected Cross-Site Scripting issues
- Affected:
- up to 1.16.66
- Fixed in:
- 1.16.66
- Disclosed:
- Jan 3, 2022
CVE-2021-25022 on NVD →
UpdraftPlus WordPress Backup Plugin <= 1.16.68 - Reflected Cross-Site Scripting via updraft_restore
medium
The UpdraftPlus WordPress Backup Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'updraft_restore' parameter in versions up to, and including, 1.16.68 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary...
- CVSS:
- 6.1
- Affected:
- 0.7.4 – 1.16.68
- Fixed in:
- 1.16.69
- Disclosed:
- Dec 28, 2021
CVE-2021-25089 on NVD →
UpdraftPlus WordPress Backup Plugin <= 1.16.65 - Reflected Cross-Site Scripting
medium
The UpdraftPlus WordPress Backup Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'backup_timestamp' & 'job_id' parameters in versions up to, and including, 1.16.65 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inje...
- CVSS:
- 6.1
- Affected:
- up to 1.16.66
- Fixed in:
- 1.16.66
- Disclosed:
- Dec 6, 2021
CVE-2021-25022 on NVD →
UpdraftPlus < 1.16.59 - Authenticated (Admin+) Local File Inclusion
high
The UpdraftPlus plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.16.56 via the updraft_service settings. This makes it possible for authenticated attackers, with administrator-level permissions and above, to include and execute arbitrary files on the server, allowing the ex...
- CVSS:
- 7.2
- Affected:
- up to 1.16.56
- Fixed in:
- 1.16.59
- Disclosed:
- Jul 12, 2021
UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.16.59
unknown
The UpdraftPlus plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.16.56 via the updraft_service settings. This makes it possible for authenticated attackers, with administrator-level permissions and above, to include and execute arbitrary files on the server, allowing the ex...
- Affected:
- up to 1.16.59
- Fixed in:
- 1.16.59
- Disclosed:
- Jul 12, 2021
UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.16.59
unknown
Local File Inclusion (LFI) vulnerability discovered by WPScanTeam in WordPress UpdraftPlus plugin (versions <= 1.16.58).
- Affected:
- up to 1.16.59
- Fixed in:
- 1.16.59
- Disclosed:
- Jul 12, 2021
UpdraftPlus WordPress Backup Plugin < 1.6.59 - Stored Cross-Site Scripting
medium
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft_service settings, allowing high privilege users to set malicious JavaScript payload in it and leading to a Stored Cross-Site Scripting issue
- CVSS:
- 4.8
- Affected:
- up to 1.6.59
- Fixed in:
- 1.6.59
- Disclosed:
- May 9, 2021
CVE-2021-24423 on NVD →
UpdraftPlus <= 1.9.63 and UpdraftPlus (paid) <= 2.9.63 - Cross-Site Scripting
medium
The UpdraftPlus free plugin before 1.9.64 (and UpdraftPlus paid before 2.9.64) are vulnerable to Cross-Site Scripting via add_query_arg() and remove_query_arg().
- CVSS:
- 6.1
- Affected:
- up to 1.9.64
- Fixed in:
- 1.9.64
- Disclosed:
- Sep 22, 2020
CVE-2015-9360 on NVD →
UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.13.5
unknown
[en] The updraftplus plugin before 1.13.5 for WordPress has XSS in rare cases where an attacker controls a string logged to a log file.
- Affected:
- up to 1.13.5
- Fixed in:
- 1.13.5
- Disclosed:
- Aug 28, 2019
CVE-2017-18593 on NVD →
UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.9.64
unknown
[en] The updraftplus plugin before 1.9.64 for WordPress has XSS via add_query_arg() and remove_query_arg().
- Affected:
- up to 1.9.64
- Fixed in:
- 1.9.64
- Disclosed:
- Aug 28, 2019
CVE-2015-9360 on NVD →
UpdraftPlus: WP Backup & Migration Plugin [updraftplus] <= 1.13.12
unknown
[en] The UpdraftPlus plugin through 1.13.12 for WordPress has SSRF in the updraft_ajax_handler function in /wp-content/plugins/updraftplus/admin.php via an httpget subaction. NOTE: the vendor reports that this does not cross a privilege boundary
- Affected:
- up to 1.13.12
- Fixed in:
- 1.13.12
- Disclosed:
- Nov 17, 2017
CVE-2017-16870 on NVD →
UpdraftPlus: WP Backup & Migration Plugin [updraftplus] <= 1.13.12
unknown
[en] The UpdraftPlus plugin through 1.13.12 for WordPress allows remote PHP code execution because the plupload_action function in /wp-content/plugins/updraftplus/admin.php has a race condition before deleting a file associated with the name parameter. NOTE: the vendor reports that this does not cross a privilege bound...
- Affected:
- up to 1.13.12
- Fixed in:
- 1.13.12
- Disclosed:
- Nov 17, 2017
CVE-2017-16871 on NVD →
UpdraftPlus <= 1.13.4 - Stored Cross-Site Scripting
medium
The updraftplus plugin before 1.13.5 for WordPress has XSS in rare cases where an attacker controls a string logged to a log file.
- CVSS:
- 5.4
- Affected:
- up to 1.13.4
- Fixed in:
- 1.13.5
- Disclosed:
- Aug 8, 2017
CVE-2017-18593 on NVD →
UpdraftPlus WordPress Backup <= 1.9.6.3 - Cross-Site Scripting
medium
The UpdraftPlus WordPress plugin for WordPress is vulnerable to Cross-Site Scripting via the 'add_query_arg()' and 'remove_query_arg()' functions in versions up to, and including, 1.9.6.3 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts tha...
- CVSS:
- 6.1
- Affected:
- up to 1.9.6.3
- Fixed in:
- 1.9.6.4
- Disclosed:
- Apr 20, 2015
UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.9.6.4
unknown
The UpdraftPlus WordPress plugin for WordPress is vulnerable to Cross-Site Scripting via the 'add_query_arg()' and 'remove_query_arg()' functions in versions up to, and including, 1.9.6.3 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts tha...
- Affected:
- up to 1.9.6.4
- Fixed in:
- 1.9.6.4
- Disclosed:
- Apr 20, 2015
UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.9.6.4
unknown
This plugin is prone to a cross site scripting vulnerability, because of the misuse of the add_query_arg() and remove_query_arg() functions.
Update the plugin.
- Affected:
- up to 1.9.6.4
- Fixed in:
- 1.9.6.4
- Disclosed:
- Apr 20, 2015
UpdraftPlus WordPress Backup Plugin <= 1.9.50 - Nonce Leak to Authorization Bypass
critical
The UpdraftPlus WordPress Backup Plugin for WordPress is vulnerable to nonce leak which leads to authorization bypass in versions up to, and including, 1.9.50. This is due to incorrect use of several 'admin_action_' hooks. This makes it possible for authenticated attackers to arbitrarily upload files, download backups...
- CVSS:
- 9.9
- Affected:
- up to 1.9.51
- Fixed in:
- 1.9.51
- Disclosed:
- Feb 3, 2015
UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.9.51
unknown
The UpdraftPlus WordPress Backup Plugin for WordPress is vulnerable to nonce leak which leads to authorization bypass in versions up to, and including, 1.9.50. This is due to incorrect use of several 'admin_action_' hooks. This makes it possible for authenticated attackers to arbitrarily upload files, download backups...
- Affected:
- up to 1.9.51
- Fixed in:
- 1.9.51
- Disclosed:
- Feb 3, 2015
UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.9.51
unknown
This plugin is prone to a privilege escalation vulnerability.
Upgrade the plugin.
- Affected:
- up to 1.9.51
- Fixed in:
- 1.9.51
- Disclosed:
- Feb 3, 2015
UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.16.59
unknown
The plugin did not validate its updraft_service settings, and using the user supplied value to include the related file, leading to a Local File Inclusion issue
- Affected:
- up to 1.16.59
- Fixed in:
- 1.16.59
UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.25.1
unknown
- Affected:
- up to 1.25.1
- Fixed in:
- 1.25.1
CVE-2025-0215 on NVD →