Record summary

CVE-2022-0633 has a selected CVSS score of 6.5 (medium).

Description

The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download the most recent site & database backup.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · May 4, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

Affected products and versions

3
ProductSourceVersion rangeStatus

UpdraftPlus WordPress Backup Plugin (Free)

Browse UpdraftPlus / UpdraftPlus WordPress Backup Plugin (Free)
CVE List1.22.3 to < 1.22.3affected

UpdraftPlus WordPress Backup Plugin (Premium)

Browse UpdraftPlus / UpdraftPlus WordPress Backup Plugin (Premium)
CVE List2.22.3 to < 2.22.3affected
VulnCheckVersion data not supplied

References

5