plugin

Updraftplus Pro Vulnerabilities

2 known security issues reported for the Updraftplus Pro WordPress plugin. Most recent disclosed Feb 17, 2022.

2 medium

Running Updraftplus Pro on your site? Check whether your installed version is affected.

Scan your site free

UpdraftPlus WordPress Backup Plugin < 1.22.3 - Sensitive Information Disclosure

medium

The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download the most recent site & database backup. The UpdraftPl...

CVSS:
6.5
Affected:
up to 2.22.3
Fixed in:
2.22.3
Disclosed:
Feb 17, 2022

CVE-2022-0633 on NVD →

UpdraftPlus <= 1.9.63 and UpdraftPlus (paid) <= 2.9.63 - Cross-Site Scripting

medium

The UpdraftPlus free plugin before 1.9.64 (and UpdraftPlus paid before 2.9.64) are vulnerable to Cross-Site Scripting via add_query_arg() and remove_query_arg().

CVSS:
6.1
Affected:
up to 2.9.64
Fixed in:
2.9.64
Disclosed:
Sep 22, 2020

CVE-2015-9360 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database