UpdraftPlus WordPress Backup Plugin < 1.22.3 - Sensitive Information Disclosure
medium
The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download the most recent site & database backup.
The UpdraftPl...
- CVSS:
- 6.5
- Affected:
- up to 2.22.3
- Fixed in:
- 2.22.3
- Disclosed:
- Feb 17, 2022
CVE-2022-0633 on NVD →
UpdraftPlus <= 1.9.63 and UpdraftPlus (paid) <= 2.9.63 - Cross-Site Scripting
medium
The UpdraftPlus free plugin before 1.9.64 (and UpdraftPlus paid before 2.9.64) are vulnerable to Cross-Site Scripting via add_query_arg() and remove_query_arg().
- CVSS:
- 6.1
- Affected:
- up to 2.9.64
- Fixed in:
- 2.9.64
- Disclosed:
- Sep 22, 2020
CVE-2015-9360 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database