Unknown Updraftplus Wordpress Backup Plugin vulnerabilities

4 known vulnerabilities affecting unknown/updraftplus_wordpress_backup_plugin.

Total CVEs
4
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2022-0864MEDIUMCVSS 6.1PoC≥ 1.22.9, < 1.22.92022-04-04
CVE-2022-0864 [MEDIUM] CWE-79 CVE-2022-0864: The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.
cvelistv5nvd
CVE-2021-25089MEDIUMCVSS 6.1≥ 1.16.69, < 1.16.692022-02-01
CVE-2021-25089 [MEDIUM] CWE-79 CVE-2021-25089: The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.69 does not sanitise and escape The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.69 does not sanitise and escape the updraft_restore parameter before outputting it back in the Restore page, leading to a Reflected Cross-Site Scripting
cvelistv5nvd
CVE-2021-24423MEDIUMCVSS 4.8≥ 1.6.59, < 1.6.592022-01-24
CVE-2021-24423 [MEDIUM] CWE-79 CVE-2021-24423: The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft_service settings, allowing high privilege users to set malicious JavaScript payload in it and leading to a Stored Cross-Site Scripting issue
cvelistv5nvd
CVE-2021-25022MEDIUMCVSS 6.1≥ 1.16.66, < 1.16.662022-01-03
CVE-2021-25022 [MEDIUM] CWE-79 CVE-2021-25022: The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.66 does not sanitise and escape The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.66 does not sanitise and escape the backup_timestamp and job_id parameter before outputting then back in admin pages, leading to Reflected Cross-Site Scripting issues
cvelistv5nvd