UpdraftPlus develops a suite of WordPress backup, security, and optimization plugins that sit within millions of website installations, making their vulnerability exposure consequential despite a compact product portfolio. The recurring weakness classes—cross-site scripting, cross-site request forgery, authorization bypass, code injection, and path traversal—reflect the web-application and administrative-interface context of WordPress plugins, and the vendor's disclosures frequently acquire public exploit code. Defenders should treat this vendor's security advisories as high-priority for any WordPress site running affected plugins; current exploitation and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Updraftplus over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0864MEDIUM The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval parameter before outputting it back in an admin page, leadi | Apr 4, 2022 | 6.1 | 34 | NO | YES |
CVE-2023-0157MEDIUM The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not escape the content of log files before outputting it to the plugin admin page, allowing an authorized user (ad | Apr 10, 2023 | 4.8 | 33 | NO | NO |
CVE-2023-1119MEDIUM The WP-Optimize WordPress plugin before 3.2.13, SrbTransLatin WordPress plugin before 2.4.1 use a third-party library that removes the escaping on some HTML characters, leading to | Jul 10, 2023 | 6.1 | 30 | NO | YES |
CVE-2017-16871HIGH The UpdraftPlus plugin through 1.13.12 for WordPress allows remote PHP code execution because the plupload_action function in /wp-content/plugins/updraftplus/admin.php has a race c | Nov 17, 2017 | 8.1 | 26 | NO | NO |
CVE-2017-16870HIGH The UpdraftPlus plugin through 1.13.12 for WordPress has SSRF in the updraft_ajax_handler function in /wp-content/plugins/updraftplus/admin.php via an httpget subaction. NOTE: the | Nov 17, 2017 | 8.1 | 25 | NO | NO |
CVE-2022-0633MEDIUM The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a backup's nonce identifier, whi | Feb 17, 2022 | 6.5 | 23 | NO | NO |
CVE-2023-0156MEDIUM The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not limit what log files to display in it's settings pages, allowing an authorized user (admin+) to view the conte | Apr 10, 2023 | 4.9 | 22 | NO | NO |
CVE-2021-25022MEDIUM The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.66 does not sanitise and escape the backup_timestamp and job_id parameter before outputting then back in admin | Jan 3, 2022 | 6.1 | 22 | NO | NO |
CVE-2021-25089MEDIUM The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.69 does not sanitise and escape the updraft_restore parameter before outputting it back in the Restore page, le | Feb 1, 2022 | 6.1 | 21 | NO | NO |
CVE-2022-4097MEDIUM The All-In-One Security (AIOS) WordPress plugin before 5.0.8 is susceptible to IP Spoofing attacks, which can lead to bypassed security features (like IP blocks, rate limiting, bru | Dec 12, 2022 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Updraftplus.
Media articles that mention a CVE ID that affects a product developed by Updraftplus — matched by CVE ID, not by vendor name.