CVE · Medium

CVE-2021-25089 — UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.16.69

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-25089 UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.16.69 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 1.16.69 1.16.69 2021-12-28

CVE-2021-25089

The UpdraftPlus backup plugin for WordPress contains a reflected cross-site scripting vulnerability in versions 1.16.68 and earlier through the 'updraft_restore' parameter, which fails to properly sanitize user input and escape output. Unauthenticated attackers can exploit this flaw by crafting a malicious link that, when clicked by a user, executes injected JavaScript code in their browser. The vulnerability was fixed in version 1.16.69.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.