plugin

Updraftplus Vulnerabilities

43 known security issues reported for the Updraftplus WordPress plugin. Most recent disclosed Jun 10, 2026.

2 critical 3 high 12 medium

Running Updraftplus on your site? Check whether your installed version is affected.

Scan your site free

UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 (free) < 2.26.5 (premium) - Unauthenticated Authentication Bypass via UpdraftCentral udrpc

critical

The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.4 (free) and versions up to 2.26.5 (premium) via the UpdraftPlus_Remote_Communications_V2::wp_loaded function. This is due to insufficient validation of the remote communi...

CVSS:
9.8
Affected:
2.0 – 2.26.5
Fixed in:
2.26.5
Disclosed:
Jun 10, 2026

CVE-2026-10795 on NVD →

UpdraftPlus - Backup/Restore <= 1.24.12 - Reflected Cross-Site Scripting

medium

The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the showdata and initiate_restore parameters in all versions up to, and including, 1.24.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attacke...

CVSS:
6.1
Affected:
up to 1.24.12
Fixed in:
1.25.1
Disclosed:
Jan 15, 2025

CVE-2025-0215 on NVD →

UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.24.12

unknown

[en] The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions from 1.23.8 to 1.24.11 via deserialization of untrusted input in the 'recursive_unserialized_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No kn...

Affected:
up to 1.24.12
Fixed in:
1.24.12
Disclosed:
Jan 4, 2025

CVE-2024-10957 on NVD →

UpdraftPlus: WP Backup & Migration Plugin 1.23.8 - 1.24.11 - Unauthenticated PHP Object Injection

high

The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions from 1.23.8 to 1.24.11 via deserialization of untrusted input in the 'recursive_unserialized_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known P...

CVSS:
8.8
Affected:
1.23.8 – 1.24.11
Fixed in:
1.24.12
Disclosed:
Jan 3, 2025

CVE-2024-10957 on NVD →

UpdraftPlus <= 1.23.10 - Cross-Site Request Forgery to Google Drive Storage Update

medium

The UpdraftPlus: WordPress Backup & Migration Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.23.10. This is due to a lack of nonce validation and insufficient validation of the instance_id on the 'updraftmethod-googledrive-auth' action used to update Goog...

CVSS:
5.4
Affected:
up to 1.23.10
Fixed in:
1.23.11
Disclosed:
Nov 7, 2023

CVE-2023-5982 on NVD →

UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.23.11

unknown

[en] The UpdraftPlus: WordPress Backup & Migration Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.23.10. This is due to a lack of nonce validation and insufficient validation of the instance_id on the 'updraftmethod-googledrive-auth' action used to update...

Affected:
up to 1.23.11
Fixed in:
1.23.11
Disclosed:
Nov 7, 2023

CVE-2023-5982 on NVD →

UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.23.4

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in UpdraftPlus.Com, DavidAnderson UpdraftPlus WordPress Backup Plugin <= 1.23.3 versions leads to sitewide Cross-Site Scripting (XSS).

Affected:
up to 1.23.4
Fixed in:
1.23.4
Disclosed:
Jun 22, 2023

CVE-2023-32960 on NVD →

UpdraftPlus <= 1.23.3 - Cross-Site Request Forgery to Cross-Site Scripting via action_authenticate_storage

medium

The UpdraftPlus plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.23.3. This is due to missing or incorrect nonce validation on the action_authenticate_storage function. This makes it possible for unauthenticated attackers to inject JavaScript into a parameter in the a...

CVSS:
6.1
Affected:
up to 1.23.3
Fixed in:
1.23.4
Disclosed:
May 18, 2023

CVE-2023-32960 on NVD →

UpdraftPlus 1.22.14 to 1.23.2 and UpdraftPlus (Premium) 2.22.14 to 2.23.2 - Privilege Escalation via updraft_central_ajax_handler

high

The UpdraftPlus plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the 'updraft_central_ajax_handler' function in versions from 1.22.14 to 1.23.2 inclusive, and 2.22.14 to 2.23.2 of the premium version. This allows authenticated attackers, with subscriber-level permissions or abo...

CVSS:
8.8
Affected:
1.22.14 – 1.23.2, 2.22.14 – 2.23.2
Fixed in:
1.23.3
Disclosed:
Mar 16, 2023

UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] >= 1.22.14 - <= 1.23.2

unknown

Update the WordPress UpdraftPlus plugin to the latest available version (at least 1.23.3). An unknown person discovered and reported this Broken Access Control vulnerability in WordPress UpdraftPlus Plugin. This vulnerability has been fixed in version 1.23.3.

Affected:
1.22.14 – 1.23.2
Fixed in:
1.23.2
Disclosed:
Mar 16, 2023

UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] >= 2.22.14 - <= 2.23.2

unknown

Update the WordPress UpdraftPlus PRO plugin to the latest available version (at least 2.23.3). An unknown person discovered and reported this Broken Access Control vulnerability in WordPress UpdraftPlus Plugin. This vulnerability has been fixed in version 2.23.3.

Affected:
2.22.14 – 2.23.2
Fixed in:
2.23.2
Disclosed:
Mar 16, 2023

UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] >= 1.22.14 - <= 1.23.2

unknown

The UpdraftPlus plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the 'updraft_central_ajax_handler' function in versions from 1.22.14 to 1.23.2 inclusive, and 2.22.14 to 2.23.2 of the premium version. This allows authenticated attackers, with subscriber-level permissions or abo...

Affected:
1.22.14 – 1.23.2
Fixed in:
1.23.2
Disclosed:
Mar 16, 2023

UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.23.1

unknown

Update the WordPress UpdraftPlus Extension plugin to the latest available version (at least 1.23.1). Unknown discovered and reported this Sensitive Data Exposure vulnerability in WordPress UpdraftPlus Plugin. This vulnerability has been fixed in version 1.23.1.

Affected:
up to 1.23.1
Fixed in:
1.23.1
Disclosed:
Mar 9, 2023

UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.23.1

unknown

Update the WordPress MainWP UpdraftPlus Extension plugin to the latest available version (at least 1.23.1). Unknown discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress UpdraftPlus Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted action...

Affected:
up to 1.23.1
Fixed in:
1.23.1
Disclosed:
Mar 9, 2023

Updraft Plus <= 1.22.24 - Information Disclosure via updraft_ajaxrestore

medium

The Updraft Plus plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 1.22.24. This is due to the fact that the 'updraft_ajaxrestore' function generates a log file containing system configuration information. This makes it possible for unauthenticated attackers to trigger gener...

CVSS:
5.3
Affected:
up to 1.22.24
Fixed in:
1.23.1
Disclosed:
Mar 8, 2023

UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.23.1

unknown

The Updraft Plus plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 1.22.24. This is due to the fact that the 'updraft_ajaxrestore' function generates a log file containing system configuration information. This makes it possible for unauthenticated attackers to trigger gener...

Affected:
up to 1.23.1
Fixed in:
1.23.1
Disclosed:
Mar 8, 2023

UpdraftPlus WordPress Backup Plugin < 1.22.9 Reflected Cross-Site Scripting

medium

The "UpdraftPlus WordPress Backup Plugin" plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'updraft_interval' parameter in versions up to 1.22.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...

CVSS:
6.1
Affected:
up to 1.22.9
Fixed in:
1.22.9
Disclosed:
Apr 7, 2022

CVE-2022-0864 on NVD →

UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.22.9

unknown

[en] The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.

Affected:
up to 1.22.9
Fixed in:
1.22.9
Disclosed:
Apr 4, 2022

CVE-2022-0864 on NVD →

UpdraftPlus WordPress Backup Plugin < 1.22.3 - Sensitive Information Disclosure

medium

The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download the most recent site & database backup. The UpdraftPl...

CVSS:
6.5
Affected:
1.16.7 – 1.22.3
Fixed in:
1.22.3
Disclosed:
Feb 17, 2022

CVE-2022-0633 on NVD →

UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.22.3

unknown

[en] The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download the most recent site & database backup.

Affected:
up to 1.22.3
Fixed in:
1.22.3
Disclosed:
Feb 17, 2022

CVE-2022-0633 on NVD →

UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.16.69

unknown

[en] The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.69 does not sanitise and escape the updraft_restore parameter before outputting it back in the Restore page, leading to a Reflected Cross-Site Scripting

Affected:
up to 1.16.69
Fixed in:
1.16.69
Disclosed:
Feb 1, 2022

CVE-2021-25089 on NVD →

UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.6.59

unknown

[en] The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft_service settings, allowing high privilege users to set malicious JavaScript payload in it and leading to a Stored Cross-Site Scripting issue

Affected:
up to 1.6.59
Fixed in:
1.6.59
Disclosed:
Jan 24, 2022

CVE-2021-24423 on NVD →

UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.16.66

unknown

[en] The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.66 does not sanitise and escape the backup_timestamp and job_id parameter before outputting then back in admin pages, leading to Reflected Cross-Site Scripting issues

Affected:
up to 1.16.66
Fixed in:
1.16.66
Disclosed:
Jan 3, 2022

CVE-2021-25022 on NVD →

UpdraftPlus WordPress Backup Plugin <= 1.16.68 - Reflected Cross-Site Scripting via updraft_restore

medium

The UpdraftPlus WordPress Backup Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'updraft_restore' parameter in versions up to, and including, 1.16.68 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary...

CVSS:
6.1
Affected:
0.7.4 – 1.16.68
Fixed in:
1.16.69
Disclosed:
Dec 28, 2021

CVE-2021-25089 on NVD →

UpdraftPlus WordPress Backup Plugin <= 1.16.65 - Reflected Cross-Site Scripting

medium

The UpdraftPlus WordPress Backup Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'backup_timestamp' & 'job_id' parameters in versions up to, and including, 1.16.65 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inje...

CVSS:
6.1
Affected:
up to 1.16.66
Fixed in:
1.16.66
Disclosed:
Dec 6, 2021

CVE-2021-25022 on NVD →

UpdraftPlus < 1.16.59 - Authenticated (Admin+) Local File Inclusion

high

The UpdraftPlus plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.16.56 via the updraft_service settings. This makes it possible for authenticated attackers, with administrator-level permissions and above, to include and execute arbitrary files on the server, allowing the ex...

CVSS:
7.2
Affected:
up to 1.16.56
Fixed in:
1.16.59
Disclosed:
Jul 12, 2021

UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.16.59

unknown

The UpdraftPlus plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.16.56 via the updraft_service settings. This makes it possible for authenticated attackers, with administrator-level permissions and above, to include and execute arbitrary files on the server, allowing the ex...

Affected:
up to 1.16.59
Fixed in:
1.16.59
Disclosed:
Jul 12, 2021

UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.16.59

unknown

Local File Inclusion (LFI) vulnerability discovered by WPScanTeam in WordPress UpdraftPlus plugin (versions <= 1.16.58).

Affected:
up to 1.16.59
Fixed in:
1.16.59
Disclosed:
Jul 12, 2021

UpdraftPlus WordPress Backup Plugin < 1.6.59 - Stored Cross-Site Scripting

medium

The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft_service settings, allowing high privilege users to set malicious JavaScript payload in it and leading to a Stored Cross-Site Scripting issue

CVSS:
4.8
Affected:
up to 1.6.59
Fixed in:
1.6.59
Disclosed:
May 9, 2021

CVE-2021-24423 on NVD →

UpdraftPlus <= 1.9.63 and UpdraftPlus (paid) <= 2.9.63 - Cross-Site Scripting

medium

The UpdraftPlus free plugin before 1.9.64 (and UpdraftPlus paid before 2.9.64) are vulnerable to Cross-Site Scripting via add_query_arg() and remove_query_arg().

CVSS:
6.1
Affected:
up to 1.9.64
Fixed in:
1.9.64
Disclosed:
Sep 22, 2020

CVE-2015-9360 on NVD →

UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.13.5

unknown

[en] The updraftplus plugin before 1.13.5 for WordPress has XSS in rare cases where an attacker controls a string logged to a log file.

Affected:
up to 1.13.5
Fixed in:
1.13.5
Disclosed:
Aug 28, 2019

CVE-2017-18593 on NVD →

UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.9.64

unknown

[en] The updraftplus plugin before 1.9.64 for WordPress has XSS via add_query_arg() and remove_query_arg().

Affected:
up to 1.9.64
Fixed in:
1.9.64
Disclosed:
Aug 28, 2019

CVE-2015-9360 on NVD →

UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] <= 1.13.12

unknown

[en] The UpdraftPlus plugin through 1.13.12 for WordPress has SSRF in the updraft_ajax_handler function in /wp-content/plugins/updraftplus/admin.php via an httpget subaction. NOTE: the vendor reports that this does not cross a privilege boundary

Affected:
up to 1.13.12
Fixed in:
1.13.12
Disclosed:
Nov 17, 2017

CVE-2017-16870 on NVD →

UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] <= 1.13.12

unknown

[en] The UpdraftPlus plugin through 1.13.12 for WordPress allows remote PHP code execution because the plupload_action function in /wp-content/plugins/updraftplus/admin.php has a race condition before deleting a file associated with the name parameter. NOTE: the vendor reports that this does not cross a privilege bound...

Affected:
up to 1.13.12
Fixed in:
1.13.12
Disclosed:
Nov 17, 2017

CVE-2017-16871 on NVD →

UpdraftPlus <= 1.13.4 - Stored Cross-Site Scripting

medium

The updraftplus plugin before 1.13.5 for WordPress has XSS in rare cases where an attacker controls a string logged to a log file.

CVSS:
5.4
Affected:
up to 1.13.4
Fixed in:
1.13.5
Disclosed:
Aug 8, 2017

CVE-2017-18593 on NVD →

UpdraftPlus WordPress Backup <= 1.9.6.3 - Cross-Site Scripting

medium

The UpdraftPlus WordPress plugin for WordPress is vulnerable to Cross-Site Scripting via the 'add_query_arg()' and 'remove_query_arg()' functions in versions up to, and including, 1.9.6.3 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts tha...

CVSS:
6.1
Affected:
up to 1.9.6.3
Fixed in:
1.9.6.4
Disclosed:
Apr 20, 2015

UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.9.6.4

unknown

The UpdraftPlus WordPress plugin for WordPress is vulnerable to Cross-Site Scripting via the 'add_query_arg()' and 'remove_query_arg()' functions in versions up to, and including, 1.9.6.3 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts tha...

Affected:
up to 1.9.6.4
Fixed in:
1.9.6.4
Disclosed:
Apr 20, 2015

UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.9.6.4

unknown

This plugin is prone to a cross site scripting vulnerability, because of the misuse of the add_query_arg() and remove_query_arg() functions. Update the plugin.

Affected:
up to 1.9.6.4
Fixed in:
1.9.6.4
Disclosed:
Apr 20, 2015

UpdraftPlus WordPress Backup Plugin <= 1.9.50 - Nonce Leak to Authorization Bypass

critical

The UpdraftPlus WordPress Backup Plugin for WordPress is vulnerable to nonce leak which leads to authorization bypass in versions up to, and including, 1.9.50. This is due to incorrect use of several 'admin_action_' hooks. This makes it possible for authenticated attackers to arbitrarily upload files, download backups...

CVSS:
9.9
Affected:
up to 1.9.51
Fixed in:
1.9.51
Disclosed:
Feb 3, 2015

UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.9.51

unknown

The UpdraftPlus WordPress Backup Plugin for WordPress is vulnerable to nonce leak which leads to authorization bypass in versions up to, and including, 1.9.50. This is due to incorrect use of several 'admin_action_' hooks. This makes it possible for authenticated attackers to arbitrarily upload files, download backups...

Affected:
up to 1.9.51
Fixed in:
1.9.51
Disclosed:
Feb 3, 2015

UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.9.51

unknown

This plugin is prone to a privilege escalation vulnerability. Upgrade the plugin.

Affected:
up to 1.9.51
Fixed in:
1.9.51
Disclosed:
Feb 3, 2015

UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.16.59

unknown

The plugin did not validate its updraft_service settings, and using the user supplied value to include the related file, leading to a Local File Inclusion issue

Affected:
up to 1.16.59
Fixed in:
1.16.59

UpdraftPlus: WP Backup &amp; Migration Plugin [updraftplus] < 1.25.1

unknown
Affected:
up to 1.25.1
Fixed in:
1.25.1

CVE-2025-0215 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database