UpdraftPlus WordPress Backup Plugin < 1.22.3 - Sensitive Information Disclosure

2022-02-17 00:00
Marc-Alexandre Montpas

Strategic Overview

Status
Patched in 1.22.3
Affected Version1.16.7 – < 1.22.3
CVSS6.5Medium
CVECVE-2022-0633
View all UpdraftPlus: WP Backup & Migration Plugin vulnerabilities

Vulnerability Overview

The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download the most recent site & database backup. The UpdraftPlus WordPress Backup Plugin plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when performing a heartbeat function in versions up to 1.22.3. This makes it possible for authenticated attackers with minimal permissions such as a subscriber to retrieve the path to arbitrary back-up files which can subsequently be downloaded and used to gain sensitive information about the system. This also affects premium versions before before 2.22.3.

Technical Analysis

REMEDIATION: Update to version 1.22.3, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C