CVE · Medium

CVE-2021-24423 — UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.6.59

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24423 UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.6.59 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 1.6.59 1.6.59 2021-05-09

CVE-2021-24423

The UpdraftPlus WordPress Backup Plugin versions before 1.6.59 fail to properly sanitize the updraft_service settings parameter, which permits administrators and other high-privilege users to inject malicious JavaScript code that gets stored in the database. When these settings are later displayed, the stored JavaScript executes in the browsers of users viewing the plugin's settings pages, resulting in a persistent cross-site scripting vulnerability. This flaw allows privileged attackers to compromise the security of the WordPress installation and potentially target other administrators.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.