Description
WordPress Plugin UpdraftPlus WordPress Backup is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently download backups made with the plugin. WordPress Plugin UpdraftPlus WordPress Backup versions between 1.16.7 and 1.22.3 are vulnerable.
Remediation
Update to plugin version 1.22.3 or latest
References
https://jetpack.com/2022/02/17/severe-vulnerability-fixed-in-updraftplus-1-22-3/
https://updraftplus.com/updraftplus-security-release-1-22-3-2-22-3/
Related Vulnerabilities
WordPress Plugin VDZ Google Analytics or Google Tag Manager/GTM Cross-Site Scripting (1.5.5)
IBM RTC Inadequate Encryption Strength Vulnerability (CVE-2017-1701)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4300)
WordPress 2.2 Multiple Vulnerabilities (2.2)
MediaWiki Improper Access Control Vulnerability (CVE-2015-8627)