Description
WordPress Plugin UpdraftPlus WordPress Backup is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently download backups made with the plugin. WordPress Plugin UpdraftPlus WordPress Backup versions between 1.16.7 and 1.22.3 are vulnerable.
Remediation
Update to plugin version 1.22.3 or latest
References
https://jetpack.com/2022/02/17/severe-vulnerability-fixed-in-updraftplus-1-22-3/
https://updraftplus.com/updraftplus-security-release-1-22-3-2-22-3/
Related Vulnerabilities
MySQL CVE-2015-4879 Vulnerability (CVE-2015-4879)
IBM WebSEAL Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2023-38371)
ownCloud Improper Access Control Vulnerability (CVE-2016-9467)
Joomla Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-3057)
OpenSSL NULL Pointer Dereference Vulnerability (CVE-2023-0217)