Description
WordPress Plugin UpdraftPlus WordPress Backup is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently download backups made with the plugin. WordPress Plugin UpdraftPlus WordPress Backup versions between 1.16.7 and 1.22.3 are vulnerable.
Remediation
Update to plugin version 1.22.3 or latest
References
https://jetpack.com/2022/02/17/severe-vulnerability-fixed-in-updraftplus-1-22-3/
https://updraftplus.com/updraftplus-security-release-1-22-3-2-22-3/
Related Vulnerabilities
WordPress Plugin Widget Control Powered By Everyblock Cross-Site Scripting (1.0.1)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-7831)
WordPress Plugin WordPress Custom Global Variable Unspecified Vulnerability (3.0.0)