Extension WordPress
Vulnérabilités UpdraftPlus: WP Backup & Migration Plugin
Cette page rassemble les failles publiées pour UpdraftPlus: WP Backup & Migration Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de UpdraftPlus: WP Backup & Migration Plugin
17 fiches
UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 (free) < 2.26.5 (premium) – Unauthenticated Authentication Bypass via UpdraftCentral udrpc
The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.4 (free) and versions up to 2.26.5 (premium) via the UpdraftPlus_Remote_Communications_V2::wp_loaded function. This is due to…
[2.0, 2.26.5), *-1.26.4
2.26.5
10/06/2026
UpdraftPlus – Backup/Restore <= 1.24.12 – Reflected Cross-Site Scripting
The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the showdata and initiate_restore parameters in all versions up to, and including, 1.24.12 due to insufficient input sanitization and output escaping.…
*-1.24.12
1.25.1
15/01/2025
UpdraftPlus: WP Backup & Migration Plugin 1.23.8 – 1.24.11 – Unauthenticated PHP Object Injection
The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions from 1.23.8 to 1.24.11 via deserialization of untrusted input in the 'recursive_unserialized_replace' function. This makes it possible for unauthenticated…
1.23.8-1.24.11
1.24.12
03/01/2025
UpdraftPlus <= 1.23.10 – Cross-Site Request Forgery to Google Drive Storage Update
The UpdraftPlus: WordPress Backup & Migration Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.23.10. This is due to a lack of nonce validation and insufficient validation of the…
*-1.23.10
1.23.11
07/11/2023
UpdraftPlus <= 1.23.3 – Cross-Site Request Forgery to Cross-Site Scripting via action_authenticate_storage
The UpdraftPlus plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.23.3. This is due to missing or incorrect nonce validation on the action_authenticate_storage function. This makes it possible for unauthenticated attackers…
*-1.23.3
1.23.4
18/05/2023
UpdraftPlus 1.22.14 to 1.23.2 and UpdraftPlus (Premium) 2.22.14 to 2.23.2 – Privilege Escalation via updraft_central_ajax_handler
The UpdraftPlus plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the 'updraft_central_ajax_handler' function in versions from 1.22.14 to 1.23.2 inclusive, and 2.22.14 to 2.23.2 of the premium version. This allows authenticated attackers, with…
1.22.14-1.23.2, 2.22.14-2.23.2
1.23.3, 2.23.3
16/03/2023
Updraft Plus <= 1.22.24 – Information Disclosure via updraft_ajaxrestore
The Updraft Plus plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 1.22.24. This is due to the fact that the 'updraft_ajaxrestore' function generates a log file containing system configuration information. This makes…
*-1.22.24
1.23.1
08/03/2023
UpdraftPlus WordPress Backup Plugin < 1.22.9 Reflected Cross-Site Scripting
The "UpdraftPlus WordPress Backup Plugin" plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'updraft_interval' parameter in versions up to 1.22.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
[*, 1.22.9)
1.22.9
07/04/2022
UpdraftPlus WordPress Backup Plugin < 1.22.3 – Sensitive Information Disclosure
The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site…
[1.16.7, 1.22.3)
1.22.3
17/02/2022
UpdraftPlus WordPress Backup Plugin <= 1.16.68 – Reflected Cross-Site Scripting via updraft_restore
The UpdraftPlus WordPress Backup Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'updraft_restore' parameter in versions up to, and including, 1.16.68 due to insufficient input sanitization and output escaping. This makes it possible for…
0.7.4-1.16.68
1.16.69
28/12/2021
UpdraftPlus WordPress Backup Plugin <= 1.16.65 – Reflected Cross-Site Scripting
The UpdraftPlus WordPress Backup Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'backup_timestamp' & 'job_id' parameters in versions up to, and including, 1.16.65 due to insufficient input sanitization and output escaping. This makes it…
[*, 1.16.66)
1.16.66
06/12/2021
UpdraftPlus < 1.16.59 – Authenticated (Admin+) Local File Inclusion
The UpdraftPlus plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.16.56 via the updraft_service settings. This makes it possible for authenticated attackers, with administrator-level permissions and above, to include and execute…
*-1.16.56
1.16.59
12/07/2021
UpdraftPlus WordPress Backup Plugin < 1.6.59 – Stored Cross-Site Scripting
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft_service settings, allowing high privilege users to set malicious JavaScript payload in it and leading to a Stored Cross-Site Scripting issue
[*, 1.6.59)
1.6.59
09/05/2021
UpdraftPlus <= 1.9.63 and UpdraftPlus (paid) <= 2.9.63 – Cross-Site Scripting
The UpdraftPlus free plugin before 1.9.64 (and UpdraftPlus paid before 2.9.64) are vulnerable to Cross-Site Scripting via add_query_arg() and remove_query_arg().
[*, 1.9.64)
1.9.64
22/09/2020
UpdraftPlus <= 1.13.4 – Stored Cross-Site Scripting
The updraftplus plugin before 1.13.5 for WordPress has XSS in rare cases where an attacker controls a string logged to a log file.
*-1.13.4
1.13.5
08/08/2017
UpdraftPlus WordPress Backup <= 1.9.6.3 – Cross-Site Scripting
The UpdraftPlus WordPress plugin for WordPress is vulnerable to Cross-Site Scripting via the 'add_query_arg()' and 'remove_query_arg()' functions in versions up to, and including, 1.9.6.3 due to insufficient input sanitization and output escaping. This makes it possible for attackers…
*-1.9.6.3
1.9.6.4
20/04/2015
UpdraftPlus WordPress Backup Plugin <= 1.9.50 – Nonce Leak to Authorization Bypass
The UpdraftPlus WordPress Backup Plugin for WordPress is vulnerable to nonce leak which leads to authorization bypass in versions up to, and including, 1.9.50. This is due to incorrect use of several 'admin_action_' hooks. This makes it possible…
[*, 1.9.51)
1.9.51
03/02/2015
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.