CVE · Medium

CVE-2021-25022 — UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.16.66

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-25022 UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.16.66 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 1.16.66 1.16.66 2021-12-06

CVE-2021-25022

The UpdraftPlus backup plugin for WordPress contains a reflected cross-site scripting vulnerability affecting versions 1.16.65 and earlier, where the 'backup_timestamp' and 'job_id' parameters are not properly sanitized or escaped. Unauthenticated attackers can inject malicious scripts that will execute in a user's browser if they click a specially crafted link, as the plugin fails to adequately filter user input before displaying it. This vulnerability was fixed in version 1.16.66.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.