CVE-2022-0633 is a privilege escalation vulnerability in the UpdraftPlus WordPress plugin (Free versions before 1.22.3 and Premium before 2.22.3). It allows any authenticated user, even a low-privileged subscriber, to download the most recent site and database backups due to improper validation of nonce identifiers. This vulnerability has a CVSS score of 6.5 (Medium), indicating a network-based attack with low complexity and required privileges, leading to high confidentiality impact. While there is no known public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community attention with three mentions and three media articles, including reports of WordPress force-installing patches on millions of sites.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.22.3CPE matchmatch criteria | cpe:2.3:a:updraftplus:updraftplus:*:*:*:*:free:wordpress:*:* | ||
< 2.22.3CPE matchmatch criteria | cpe:2.3:a:updraftplus:updraftplus:*:*:*:*:premium:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.