Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Updraftplus

First CVE: Nov 17, 2017Active for: 9 yearsTotal CVEs: 19
25.1
VTI Score
Low

UpdraftPlus develops a suite of WordPress backup, security, and optimization plugins that sit within millions of website installations, making their vulnerability exposure consequential despite a compact product portfolio. The recurring weakness classes—cross-site scripting, cross-site request forgery, authorization bypass, code injection, and path traversal—reflect the web-application and administrative-interface context of WordPress plugins, and the vendor's disclosures frequently acquire public exploit code. Defenders should treat this vendor's security advisories as high-priority for any WordPress site running affected plugins; current exploitation and severity counts are shown alongside this summary.

FAUCET AI Generated
19
Total CVEs
More Total CVEs than 96% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
5.9
Avg CVSS Score
Higher Avg CVSS Score than 28% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Updraftplus over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 17, 2017
8 years ago
Most Recent CVE
Jun 2, 2025
417 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-0864MEDIUM
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval parameter before outputting it back in an admin page, leadi
Apr 4, 20226.134NOYES
CVE-2023-0157MEDIUM
The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not escape the content of log files before outputting it to the plugin admin page, allowing an authorized user (ad
Apr 10, 20234.833NONO
CVE-2023-1119MEDIUM
The WP-Optimize WordPress plugin before 3.2.13, SrbTransLatin WordPress plugin before 2.4.1 use a third-party library that removes the escaping on some HTML characters, leading to
Jul 10, 20236.130NOYES
CVE-2017-16871HIGH
The UpdraftPlus plugin through 1.13.12 for WordPress allows remote PHP code execution because the plupload_action function in /wp-content/plugins/updraftplus/admin.php has a race c
Nov 17, 20178.126NONO
CVE-2017-16870HIGH
The UpdraftPlus plugin through 1.13.12 for WordPress has SSRF in the updraft_ajax_handler function in /wp-content/plugins/updraftplus/admin.php via an httpget subaction. NOTE: the
Nov 17, 20178.125NONO
CVE-2022-0633MEDIUM
The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a backup's nonce identifier, whi
Feb 17, 20226.523NONO
CVE-2023-0156MEDIUM
The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not limit what log files to display in it's settings pages, allowing an authorized user (admin+) to view the conte
Apr 10, 20234.922NONO
CVE-2021-25022MEDIUM
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.66 does not sanitise and escape the backup_timestamp and job_id parameter before outputting then back in admin
Jan 3, 20226.122NONO
CVE-2021-25089MEDIUM
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.69 does not sanitise and escape the updraft_restore parameter before outputting it back in the Restore page, le
Feb 1, 20226.121NONO
CVE-2022-4097MEDIUM
The All-In-One Security (AIOS) WordPress plugin before 5.0.8 is susceptible to IP Spoofing attacks, which can lead to bypassed security features (like IP blocks, rate limiting, bru
Dec 12, 20225.320NONO
View all 19 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products19 CVEs
89%
11%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network19 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (89.5%)
High2 (10.5%)
Unknown0 (0.0%)
User Interaction
None7 (36.8%)
Unknown0 (0.0%)
Required12 (63.2%)
Privileges Required
Low1 (5.3%)
High4 (21.1%)
None14 (73.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
10.5% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Updraftplus.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Updraftplus — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Updraftplus's Products

View all 4 CNAs →

Top CWEs