Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesUpdraftPlus

UpdraftPlus vulnerabilities

UpdraftPlus has 16 known vulnerabilities in this database. The most recent published record is dated 27 Sep 2026.

Known vulnerabilities
16
Active installs
4m+
Latest version
1.26.8
Last updated
21 Sep 2026
Most recent
27 Sep 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Sensitive data exposure
CVE-2026-82841
Medium 5.3Before 1.26.8Fixed in 1.26.810 d ago
Cross-site request forgery (CSRF)
CVE-2026-76549
Medium 5.9Before 1.26.7Fixed in 1.26.727 Aug 2026
Remote code execution
CVE-2026-10795
High 8.1Up to 1.26.4Fixed in a later version (latest 1.26.8)11 Jun 2026
Cross-site scripting (XSS)
CVE-2025-0215
Medium 6.1Up to 1.24.12Fixed in a later version (latest 1.26.8)15 Jan 2025
PHP object injection
CVE-2024-10957
High 8.8Not yet publishedCheck for an update4 Jan 2025
Cross-site request forgery (CSRF)
CVE-2023-5982
Medium 5.4Up to 1.23.10Fixed in a later version (latest 1.26.8)7 Nov 2023
Cross-site scripting (XSS)
CVE-2023-32960
High 7.1Up to 1.23.3Fixed in a later version (latest 1.26.8)22 Jun 2023
Cross-site scripting (XSS)
CVE-2022-0864
Medium 6.1Before 1.22.9Fixed in 1.22.94 Apr 2022
Broken access control
CVE-2022-0633
Medium 6.5Before 2.22.3Fixed in 2.22.317 Feb 2022
Cross-site scripting (XSS)
CVE-2021-25089
Medium 6.1Before 1.16.69Fixed in 1.16.691 Feb 2022
Cross-site scripting (XSS)
CVE-2021-24423
Medium 4.8Before 1.16.59Fixed in 1.16.5924 Jan 2022
Cross-site scripting (XSS)
CVE-2021-25022
Medium 6.1Before 1.16.66Fixed in 1.16.663 Jan 2022
Cross-site scripting (XSS)
CVE-2017-18593
Medium 6.1Before 1.13.5Fixed in 1.13.528 Aug 2019
Cross-site scripting (XSS)
CVE-2015-9360
Medium 6.1Before 1.9.64Fixed in 1.9.6428 Aug 2019
Server-side request forgery (SSRF)
CVE-2017-16870
High 8.1Up to 1.13.12Fixed in a later version (latest 1.26.8)17 Nov 2017
Remote code execution
CVE-2017-16871
High 8.1Up to 1.13.12Fixed in a later version (latest 1.26.8)17 Nov 2017
Read the published descriptions
CVE-2026-82841, 27 Sep 2026
The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.8, UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 2.26.8.26 does not have any capability check in a routine that outputs its stored remote storage settings into admin pages when the site is left in a particular post-migration state, allowing any authenticated user, such as a subscriber, to retrieve the credentials of the configured backup destinations, such as passwords and secret keys. CVE record
CVE-2026-76549, 27 Aug 2026
The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one of its backup management actions, which could allow attackers to make a logged in admin restore an existing backup, reverting the site's database and files to an earlier state, via a crafted link. CVE record
CVE-2026-10795, 11 Jun 2026
The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.4 via the UpdraftPlus_Remote_Communications_V2::wp_loaded function. This is due to insufficient validation of the remote communications message format, where signature verification can be bypassed and unchecked decryption return values collapse to a predictable all-zero encryption key. This makes it possible for unauthenticated attackers to forge arbitrary RPC commands and run them as the connected administrator, such as uploading and activating a malicious plugin, which ultimately leads to remote code execution. CVE record
CVE-2025-0215, 15 Jan 2025
The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the showdata and initiate_restore parameters in all versions up to, and including, 1.24.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick an admin user into performing an action such as clicking on a link. CVE record
CVE-2024-10957, 4 Jan 2025
The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions from 1.23.8 to 1.24.11 via deserialization of untrusted input in the 'recursive_unserialized_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. An administrator must perform a search and replace action to trigger the exploit. CVE record
CVE-2023-5982, 7 Nov 2023
The UpdraftPlus: WordPress Backup & Migration Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.23.10. This is due to a lack of nonce validation and insufficient validation of the instance_id on the 'updraftmethod-googledrive-auth' action used to update Google Drive remote storage location. This makes it possible for unauthenticated attackers to modify the Google Drive location that backups are sent to via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This can make it possible for attackers to receive backups for a site which may contain sensitive information. CVE record
CVE-2023-32960, 22 Jun 2023
Cross-Site Request Forgery (CSRF) vulnerability in UpdraftPlus.Com, DavidAnderson UpdraftPlus WordPress Backup Plugin <= 1.23.3 versions leads to sitewide Cross-Site Scripting (XSS). CVE record
CVE-2022-0864, 4 Apr 2022
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability. CVE record
CVE-2022-0633, 17 Feb 2022
The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download the most recent site & database backup. CVE record
CVE-2021-25089, 1 Feb 2022
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.69 does not sanitise and escape the updraft_restore parameter before outputting it back in the Restore page, leading to a Reflected Cross-Site Scripting CVE record
CVE-2021-24423, 24 Jan 2022
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft_service settings, allowing high privilege users to set malicious JavaScript payload in it and leading to a Stored Cross-Site Scripting issue CVE record
CVE-2021-25022, 3 Jan 2022
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.66 does not sanitise and escape the backup_timestamp and job_id parameter before outputting then back in admin pages, leading to Reflected Cross-Site Scripting issues CVE record
CVE-2017-18593, 28 Aug 2019
The updraftplus plugin before 1.13.5 for WordPress has XSS in rare cases where an attacker controls a string logged to a log file. CVE record
CVE-2015-9360, 28 Aug 2019
The updraftplus plugin before 1.9.64 for WordPress has XSS via add_query_arg() and remove_query_arg(). CVE record
CVE-2017-16870, 17 Nov 2017
The UpdraftPlus plugin through 1.13.12 for WordPress has SSRF in the updraft_ajax_handler function in /wp-content/plugins/updraftplus/admin.php via an httpget subaction. NOTE: the vendor reports that this does not cross a privilege boundary CVE record
CVE-2017-16871, 17 Nov 2017
The UpdraftPlus plugin through 1.13.12 for WordPress allows remote PHP code execution because the plupload_action function in /wp-content/plugins/updraftplus/admin.php has a race condition before deleting a file associated with the name parameter. NOTE: the vendor reports that this does not cross a privilege boundary CVE record

What to do if you run UpdraftPlus

If you run UpdraftPlus, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new UpdraftPlus vulnerabilities

Free. We email you when a new vulnerability is published for UpdraftPlus, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support