WordPress security by component
UpdraftPlus WordPress Backup Plugin
Plugin description
UpdraftPlus WordPress Backup Plugin backs up, restores, and migrates WordPress files and databases using configurable storage destinations.
UpdraftPlus WordPress Backup Plugin (updraftplus) is a WordPress plugin with 13 published CVE records in this archive. The latest tracked vulnerability was published Jan 15, 2025; the highest published CVSS base score is 8.8.
Plugin slug:
updraftplusLatest vulnerability
CVE-2025-0215: UpdraftPlus: WP Backup & Migration Plugin: Cross-site scripting
UpdraftPlus: WP Backup & Migration Plugin is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
| Safe version |
|
||
|---|---|---|---|
| Jan 15, 2025 |
CVE-2025-0215
UpdraftPlus: WP Backup & Migration Plugin: Cross-site scripting
UpdraftPlus: WP Backup & Migration Plugin is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVDPending
|
| Jan 04, 2025 |
CVE-2024-10957
UpdraftPlus: WP Backup & Migration Plugin: Code execution
UpdraftPlus: WP Backup & Migration Plugin is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Nov 07, 2023 |
CVE-2023-5982
UpdraftPlus: WordPress Backup & Migration Plugin: Cross-site request forgery
UpdraftPlus: WordPress Backup & Migration Plugin is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Jun 22, 2023 |
CVE-2023-32960
Updraftplus: Cross-site scripting
Updraftplus is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Apr 04, 2022 |
CVE-2022-0864
UpdraftPlus WordPress Backup Plugin: Cross-site scripting
UpdraftPlus WordPress Backup Plugin is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Feb 17, 2022 |
CVE-2022-0633
UpdraftPlus: A security weakness
UpdraftPlus is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD6.5
|
| Feb 01, 2022 |
CVE-2021-25089
UpdraftPlus WordPress Backup Plugin: Cross-site scripting
UpdraftPlus WordPress Backup Plugin is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Jan 24, 2022 |
CVE-2021-24423
UpdraftPlus WordPress Backup Plugin: Cross-site scripting
UpdraftPlus WordPress Backup Plugin is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD4.8
|
| Jan 03, 2022 |
CVE-2021-25022
UpdraftPlus WordPress Backup Plugin: Cross-site scripting
UpdraftPlus WordPress Backup Plugin is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Aug 28, 2019 |
CVE-2017-18593
Updraftplus: Cross-site scripting
Updraftplus is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Aug 28, 2019 |
CVE-2015-9360
Updraftplus: Cross-site scripting
Updraftplus is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Nov 17, 2017 |
CVE-2017-16871
Updraftplus: A security weakness
Updraftplus is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD8.1
|
| Nov 17, 2017 |
CVE-2017-16870
Updraftplus: Server-side request forgery
Updraftplus is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVEPending
NVD8.1
|