CVE Database
/

CVE-2022-0633

Back to search

CVE-2022-0633

Published: Feb 17, 2022

Modified: Aug 2, 2024

PUBLISHED

Description

The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download the most recent site & database backup.

VendorProductVersions

UpdraftPlus

UpdraftPlus WordPress Backup Plugin (Free)

affected
1.22.3 - < 1.22.3

UpdraftPlus

UpdraftPlus WordPress Backup Plugin (Premium)

affected
2.22.3 - < 2.22.3

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now