UpdraftPlus - Backup/Restore <= 1.24.12 - Reflected Cross-Site Scripting
UpdraftPlus: WP Backup & Migration Plugin
Minimum safe version
1.25.1
Update to 1.25.1 or later to address 21 fixable vulnerabilities
WordPress UpdraftPlus Plugin <= 1.24.11 is vulnerable to PHP Object Injection
CVE-2023-5982
WordPress UpdraftPlus Plugin <= 1.22.24 is vulnerable to Sensitive Data Exposure
CVE-2023-32960
WordPress UpdraftPlus Plugin 2.22.14-2.23.2 is vulnerable to Broken Access Control
WordPress UpdraftPlus Plugin 1.22.14-1.23.2 is vulnerable to Broken Access Control
UpdraftPlus 1.22.14 to 1.23.2 and UpdraftPlus (Premium) 2.22.14 to 2.23.2 - Privilege Escalation via updraft_central_ajax_handler
WordPress UpdraftPlus Plugin <= 1.22.24 is vulnerable to Cross Site Request Forgery (CSRF)
Updraft Plus <= 1.22.24 - Information Disclosure via updraft_ajaxrestore
UpdraftPlus WordPress Backup Plugin <= 1.9.50 - Nonce Leak to Authorization Bypass
UpdraftPlus WordPress Backup <= 1.9.6.3 - Cross-Site Scripting
UpdraftPlus < 1.16.59 - Admin+ Local File Inclusion
UpdraftPlus < 1.16.59 - Authenticated (Admin+) Local File Inclusion
WordPress UpdraftPlus Backup & Restoration Plugin <= 1.9.6.3 - Cross Site Scripting
WordPress UpdraftPlus Plugin <= 1.9.50 - Privilege Escalation
WordPress UpdraftPlus plugin <= 1.16.58 - Local File Inclusion (LFI) vulnerability
UpdraftPlus WordPress Backup Plugin < 1.22.9 Reflected Cross-Site Scripting
CVE-2017-16870
CVE-2017-16871
CVE-2017-18593
UpdraftPlus <= 1.9.63 and UpdraftPlus (paid) <= 2.9.63 - Cross-Site Scripting
CVE-2021-25022
CVE-2021-24423
CVE-2021-25089
CVE-2022-0633