Warning! WordPress Plugin Vulnerability Threatens Millions of Pages

General News

Summary

This time, the vulnerability concerns the plugin named UpdraftPlus, which is installed in roughly 3 million websites running the publishing platform. The flaw in UpdraftPlus was codified under the handle CVE 2022-0633 and received a severity rating of 8.5 or High. The vulnerability allowed any active and successfully logged-in user on any WordPress website that runs UpdraftPlus to download existing site backups - something that should only be possible with elevated privileges, such as those possessed by administrators. The ability to just grab the entire backup data can lead to all sorts of issues down the road, ranging from credential theft to accessing sensitive and privileged information. The vulnerability isnt nearly as horrible as it seems, because if this action is carried out by an external bad actor, the hacker would still need to have regular access to the WordPress platform instance for the site.

Classifications

industries
Entertainment
applications
Customer Service & Support

AskAI Classifications

Labels
Cybersecurity Software Anti-Malware Software SaaS Security

Linked Companies

EnigmaSoft
$1M to $5M