AUTO-UPDATED

UpdraftPlus WordPress Vulnerability Puts 3 Million Sites At Risk via @sejournal, @martinibuster

A critical authentication bypass vulnerability in the UpdraftPlus WordPress plugin affects over 3 million websites, allowing unauthenticated attackers to execute malicious code and gain full administrative control.

Key Points

  • The vulnerability impacts all versions of the UpdraftPlus: WP Backup & Migration Plugin up to and including version 1.26.4.
  • Attackers can exploit the flaw to bypass identity verification, upload malicious plugins, and achieve remote code execution on affected servers.
  • The security failure stems from insufficient validation of remote communications messages within the UpdraftPlus_Remote_Communications_V2::wp_loaded function.
  • Security firm Wordfence reported blocking over 8,000 attempted exploits targeting this specific vulnerability within a single 24-hour period.
  • Users must update to version 1.26.5 or newer immediately to secure their websites against potential unauthorized access and site takeover.

Why it Matters

This flaw poses a severe risk to millions of WordPress users because it allows attackers to compromise websites without needing valid login credentials. Promptly updating the plugin is essential to prevent data theft, malware injection, and total loss of administrative control over affected web servers.
Search Engine Journal Published by Roger Montti
Read original