Home » Security News » Vulnerability in the UpdraftPlus plugin affects mi...

Vulnerability in the UpdraftPlus plugin affects millions of WordPress websites

Vulnerability in the UpdraftPlus plugin affects millions of WordPress websites
Deepanker Verma February 21, 2022 Security

Add Techlomedia as a preferred source on Google. Preferred Source

Every week, we see a new vulnerability impacting millions of WordPress websites. This week isn’t an exception. Now a vulnerability in the popular backup plugin UpdraftPlus has been uncovered impacting over 3 million WordPress websites. The vulnerability affects UpdraftPlus versions 1.16.7 to 1.22.2. Developers of the plugin have already issued the update to fix the vulnerability.

If you also use the UpdraftPlus plugin, update it to the latest version as soon as possible.

UpdraftPlus plugin makes it really easy to backup and restore the WordPress website. It also offers scheduled backup and auto-download options.

The vulnerability tracked as CVE-2022-0633 lets any low-level authenticated user craft a valid link to download the backup of the website including the raw database. The vulnerability is also easy to exploit.

Also see: WordPress Courses & Tutorials

Montpas, the researcher at Jetpack, found the vulnerability and reported it to UpdraftPlus developers. A day after receiving the information, developers released the update and agreed to force-install it on WordPress sites that were already using the plugin.

This is also one of the rare cases where WordPress forces auto-updates on all the websites. It is because this vulnerability is easy to exploit and gives attackers access to full website backup.

This vulnerability doesn’t impact websites that don’t support user logins or don’t hold any backups.

Follow Techlomedia on Google News to stay updated. Follow on Google News

Affiliate Disclosure:

This article may contain affiliate links. We may earn a commission on purchases made through these links at no extra cost to you.

Deepanker Verma

About the Author: Deepanker Verma

Deepanker Verma is the Founder and Editor-in-Chief of TechloMedia. He holds Engineering degree in Computer Science and has over 15 years of experience in the technology sector. Deepanker bridges the gap between complex engineering and consumer electronics. He is also a a known Security Researcher acknowledged by global giants including Apple, Microsoft, and eBay. He uses his technical background to rigorously test gadgets, focusing on performance, security, and long-term value.

Related Posts

Stay Updated with Techlomedia

Join our newsletter to receive the latest tech news, reviews, and guides directly in your inbox.