A critical authentication bypass vulnerability in the UpdraftPlus WordPress plugin affects over 3 million websites, allowing unauthenticated attackers to execute malicious code and gain full administrative control.
Key Points
- The vulnerability impacts all versions of the UpdraftPlus: WP Backup & Migration Plugin up to and including version 1.26.4.
- Attackers can exploit the flaw to bypass identity verification, upload malicious plugins, and achieve remote code execution on affected servers.
- The security failure stems from insufficient validation of remote communications messages within the
UpdraftPlus_Remote_Communications_V2::wp_loadedfunction. - Security firm Wordfence reported blocking over 8,000 attempted exploits targeting this specific vulnerability within a single 24-hour period.
- Users must update to version 1.26.5 or newer immediately to secure their websites against potential unauthorized access and site takeover.