Showing 1 vulnerability on this page for UpdraftPlus WordPress Backup Plugin (Premium)

Signals CISA KEV Ransomware Nuclei
updraftplus vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

UpdraftPlus Free < 1.22.3 & Premium < 2.22.3 - Subscriber+ Backup Download

The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download the most recent site & database backup.

CWE-863Feb 17, 2022
CVSS6.5v3.1EPSS2.07%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX