CVE Database /
CVE-2017-16870
CVE · High
CVE-2017-16870 — UpdraftPlus: WP Backup & Migration Plugin [updraftplus] <= 1.13.12
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2017-16870
|
UpdraftPlus: WP Backup & Migration Plugin [updraftplus] <= 1.13.12 |
Server-Side Request Forgery (SSRF) |
High
8.1
|
< 1.13.12
|
1.13.12 |
2017-11-17 |
—
|
CVE-2017-16870
The UpdraftPlus backup and migration plugin up to version 1.13.12 contains a server-side request forgery vulnerability in the updraft_ajax_handler function located at /wp-content/plugins/updraftplus/admin.php when processing the httpget subaction. This flaw allows an attacker to make the server perform unintended HTTP requests to arbitrary destinations. According to the vendor, this vulnerability does not require crossing privilege boundaries to be exploited.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings