Description
WordPress Plugin UpdraftPlus WordPress Backup is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently download backups made with the plugin. WordPress Plugin UpdraftPlus WordPress Backup versions between 1.16.7 and 1.22.3 are vulnerable.
Remediation
Update to plugin version 1.22.3 or latest
References
https://jetpack.com/2022/02/17/severe-vulnerability-fixed-in-updraftplus-1-22-3/
https://updraftplus.com/updraftplus-security-release-1-22-3-2-22-3/
Related Vulnerabilities
WordPress Plugin The Plus Addons for Elementor Security Bypass (4.1.10)
Nginx Improper Encoding or Escaping of Output Vulnerability (CVE-2013-4547)
WordPress URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2018-10101)
WordPress Plugin Fancy Product Designer-WooCommerce SQL Injection (4.7.4)