Plugin Vulnerability Hub
Plugin 16 known issues Latest disclosed Jan 15, 2025

UpdraftPlus: WP Backup & Migration Plugin Vulnerabilities

Review known vulnerability records for the WordPress plugin UpdraftPlus: WP Backup & Migration Plugin (`updraftplus`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2025-0215, CVE-2024-10957 and CVE-2023-5982, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
16
High or Critical
4
Patch Coverage
100%
Last Updated
Jan 15, 2025
Priority CVE Quick Links

Fast paths into UpdraftPlus: WP Backup & Migration Plugin CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
11
CVE-2024-10957 High 1.24.12
CVE-2024-10957 UpdraftPlus: WP Backup & Migration Plugin Vulnerability

UpdraftPlus: WP Backup & Migration Plugin 1.23.8 - 1.24.11 - Unauthenticated PHP Object Injection

CVE-2022-0633 Medium 1.22.3
CVE-2022-0633 UpdraftPlus: WP Backup & Migration Plugin Authorization Bypass

UpdraftPlus WordPress Backup Plugin < 1.22.3 - Sensitive Information Disclosure

CVE-2025-0215 Medium 1.25.1
CVE-2025-0215 UpdraftPlus: WP Backup & Migration Plugin Cross-Site Scripting

UpdraftPlus - Backup/Restore <= 1.24.12 - Reflected Cross-Site Scripting

CVE-2023-32960 Medium 1.23.4
CVE-2023-32960 UpdraftPlus: WP Backup & Migration Plugin Cross-Site Scripting

UpdraftPlus <= 1.23.3 - Cross-Site Request Forgery to Cross-Site Scripting via action_authenticate_storage

CVE-2022-0864 Medium 1.22.9
CVE-2022-0864 UpdraftPlus: WP Backup & Migration Plugin Cross-Site Scripting

UpdraftPlus WordPress Backup Plugin < 1.22.9 Reflected Cross-Site Scripting

CVE-2021-25089 Medium 1.16.69
CVE-2021-25089 UpdraftPlus: WP Backup & Migration Plugin Cross-Site Scripting

UpdraftPlus WordPress Backup Plugin <= 1.16.68 - Reflected Cross-Site Scripting via updraft_restore

CVE-2021-25022 Medium 1.16.66
CVE-2021-25022 UpdraftPlus: WP Backup & Migration Plugin Cross-Site Scripting

UpdraftPlus WordPress Backup Plugin <= 1.16.65 - Reflected Cross-Site Scripting

CVE-2015-9360 Medium 1.9.64
CVE-2015-9360 UpdraftPlus: WP Backup & Migration Plugin Cross-Site Scripting

UpdraftPlus <= 1.9.63 and UpdraftPlus (paid) <= 2.9.63 - Cross-Site Scripting

Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for UpdraftPlus: WP Backup & Migration Plugin so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
16 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
1 critical and 3 high severity findings.
Recent CVEs
CVE-2025-0215, CVE-2024-10957 and CVE-2023-5982
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for UpdraftPlus: WP Backup & Migration Plugin

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2025-0215
CVE-2025-0215: UpdraftPlus - Backup/Restore <= 1.24.12 - Reflected Cross-Site Scripting

The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the showdata and initiate_restore parameters in all versions up to, and including, 1.24.12 due to insufficient input sanitization and output escaping. This makes...

Published
Jan 15, 2025
Patched Release
1.25.1
Affected Versions
Versions up to 1.24.12
Next Step
Update to 1.25.1 or newer if supported.
Plugin High Patched: Yes CVE-2024-10957
CVE-2024-10957: UpdraftPlus: WP Backup & Migration Plugin 1.23.8 - 1.24.11 - Unauthenticated PHP Object Injection

The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions from 1.23.8 to 1.24.11 via deserialization of untrusted input in the 'recursive_unserialized_replace' function. This makes it possible for unauthenticated atta...

Published
Jan 03, 2025
Patched Release
1.24.12
Affected Versions
1.23.8 through 1.24.11
Next Step
Update to 1.24.12 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-5982
CVE-2023-5982: UpdraftPlus <= 1.23.10 - Cross-Site Request Forgery to Google Drive Storage Update

The UpdraftPlus: WordPress Backup & Migration Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.23.10. This is due to a lack of nonce validation and insufficient validation of the instance_id on the 'updraftmethod-goog...

Published
Nov 07, 2023
Patched Release
1.23.11
Affected Versions
Versions up to 1.23.10
Next Step
Update to 1.23.11 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-32960
CVE-2023-32960: UpdraftPlus <= 1.23.3 - Cross-Site Request Forgery to Cross-Site Scripting via action_authenticate_storage

The UpdraftPlus plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.23.3. This is due to missing or incorrect nonce validation on the action_authenticate_storage function. This makes it possible for unauthenticated attackers to inj...

Published
May 18, 2023
Patched Release
1.23.4
Affected Versions
Versions up to 1.23.3
Next Step
Update to 1.23.4 or newer if supported.
Plugin High Patched: Yes
UpdraftPlus 1.22.14 to 1.23.2 and UpdraftPlus (Premium) 2.22.14 to 2.23.2 - Privilege Escalation via updraft_central_ajax_handler

The UpdraftPlus plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the 'updraft_central_ajax_handler' function in versions from 1.22.14 to 1.23.2 inclusive, and 2.22.14 to 2.23.2 of the premium version. This allows authenticated attackers,...

Published
Mar 16, 2023
Patched Release
1.23.3
Affected Versions
1.22.14 through 1.23.2
Next Step
Update to 1.23.3 or newer if supported.
Plugin Medium Patched: Yes
Updraft Plus <= 1.22.24 - Information Disclosure via updraft_ajaxrestore

The Updraft Plus plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 1.22.24. This is due to the fact that the 'updraft_ajaxrestore' function generates a log file containing system configuration information. This makes it possible for un...

Published
Mar 08, 2023
Patched Release
1.23.1
Affected Versions
Versions up to 1.22.24
Next Step
Update to 1.23.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2022-0864
CVE-2022-0864: UpdraftPlus WordPress Backup Plugin < 1.22.9 Reflected Cross-Site Scripting

The "UpdraftPlus WordPress Backup Plugin" plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'updraft_interval' parameter in versions up to 1.22.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated atta...

Published
Apr 07, 2022
Patched Release
1.22.9
Affected Versions
Versions before 1.22.9
Next Step
Update to 1.22.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2022-0633
CVE-2022-0633: UpdraftPlus WordPress Backup Plugin < 1.22.3 - Sensitive Information Disclosure

The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download the most recent...

Published
Feb 17, 2022
Patched Release
1.22.3
Affected Versions
1.16.7 up to before 1.22.3
Next Step
Update to 1.22.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2021-25089
CVE-2021-25089: UpdraftPlus WordPress Backup Plugin <= 1.16.68 - Reflected Cross-Site Scripting via updraft_restore

The UpdraftPlus WordPress Backup Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'updraft_restore' parameter in versions up to, and including, 1.16.68 due to insufficient input sanitization and output escaping. This makes it possible for unauth...

Published
Dec 28, 2021
Patched Release
1.16.69
Affected Versions
0.7.4 through 1.16.68
Next Step
Update to 1.16.69 or newer if supported.
Plugin Medium Patched: Yes CVE-2021-25022
CVE-2021-25022: UpdraftPlus WordPress Backup Plugin <= 1.16.65 - Reflected Cross-Site Scripting

The UpdraftPlus WordPress Backup Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'backup_timestamp' & 'job_id' parameters in versions up to, and including, 1.16.65 due to insufficient input sanitization and output escaping. This makes it possib...

Published
Dec 06, 2021
Patched Release
1.16.66
Affected Versions
Versions before 1.16.66
Next Step
Update to 1.16.66 or newer if supported.
Plugin High Patched: Yes
UpdraftPlus < 1.16.59 - Authenticated (Admin+) Local File Inclusion

The UpdraftPlus plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.16.56 via the updraft_service settings. This makes it possible for authenticated attackers, with administrator-level permissions and above, to include and execute arbitr...

Published
Jul 12, 2021
Patched Release
1.16.59
Affected Versions
Versions up to 1.16.56
Next Step
Update to 1.16.59 or newer if supported.
Plugin Medium Patched: Yes CVE-2021-24423
CVE-2021-24423: UpdraftPlus WordPress Backup Plugin < 1.6.59 - Stored Cross-Site Scripting

The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft_service settings, allowing high privilege users to set malicious JavaScript payload in it and leading to a Stored Cross-Site Scripting issue

Published
May 09, 2021
Patched Release
1.6.59
Affected Versions
Versions before 1.6.59
Next Step
Update to 1.6.59 or newer if supported.