CVE · High

CVE-2017-16870 — UpdraftPlus: WP Backup & Migration Plugin [updraftplus] <= 1.13.12

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2017-16870 UpdraftPlus: WP Backup & Migration Plugin [updraftplus] <= 1.13.12 Server-Side Request Forgery (SSRF) High 8.1 < 1.13.12 1.13.12 2017-11-17

CVE-2017-16870

The UpdraftPlus backup and migration plugin up to version 1.13.12 contains a server-side request forgery vulnerability in the updraft_ajax_handler function located at /wp-content/plugins/updraftplus/admin.php when processing the httpget subaction. This flaw allows an attacker to make the server perform unintended HTTP requests to arbitrary destinations. According to the vendor, this vulnerability does not require crossing privilege boundaries to be exploited.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.