6.5

CVE-2022-0633

Exploit

UpdraftPlus WordPress Backup Plugin < 1.22.3 - Sensitive Information Disclosure

The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download the most recent site & database backup.
Mögliche Gegenmaßnahme
UpdraftPlus: WP Backup & Migration Plugin: Update to version 1.22.3, or a newer patched version
UpdraftPlus WordPress Backup Plugin (Premium): Update to version 2.22.3, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt UpdraftPlus: WP Backup & Migration Plugin
Version [1.16.7, 1.22.3)
SystemWordPress Plugin
Produkt UpdraftPlus WordPress Backup Plugin (Premium)
Version [*, 2.22.3)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
UpdraftplusUpdraftplus SwEditionfree SwPlatformwordpress Version < 1.22.3
UpdraftplusUpdraftplus SwEditionpremium SwPlatformwordpress Version < 2.22.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.4% 0.8
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.