What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in UpdraftPlus.Com, DavidAnderson UpdraftPlus WordPress Backup Plugin <= 1.23.3 versions leads to sitewide Cross-Site Scripting (XSS).
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in UpdraftPlus.Com, DavidAnderson UpdraftPlus WordPress Backup Plugin <= 1.23.3 versions leads to sitewide Cross-Site Scripting (XSS).
Explanation of Vulnerability in Simple Terms
UpdraftPlus versions up to 1.23.3 contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to perform unauthorized actions on a WordPress site. An attacker can trick a logged-in site administrator into visiting a malicious webpage, which then executes unwanted backup, restore, or settings changes without the admin's knowledge. The vulnerability affects the plugin's core functionality and requires user interaction to exploit.
What an attacker can do
Trick a logged-in admin into performing unauthorized backup, restore, or settings changes via a malicious webpage.
Potential impact on your site
An attacker can modify backup settings, trigger unwanted restores, or alter plugin configuration without your consent.
Conditions required to exploit
Site admin must be logged into WordPress and visit an attacker-controlled webpage while authenticated.
Key dates
External resources
Related vulnerabilities