updraftplus Vulnerabilities and Affected Products
Vulnerabilities associated with UpdraftPlus WordPress Backup Plugin (Premium).
Products
Clear product- updraftplus2 vulnerabilities
- UpdraftPlus WordPress Backup Plugin (Free)1 vulnerability
- UpdraftPlus WordPress Backup Plugin (Premium)1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-0633MEDIUM | UpdraftPlus Free < 1.22.3 & Premium < 2.22.3 - Subscriber+ Backup DownloadThe UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download the most recent site & database backup. CWE-863Feb 17, 2022 | CVSS6.5v3.1 | EPSS2.07% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |