CVE-2022-0633
The UpdraftPlus backup plugin for WordPress contains an authorization bypass flaw in versions prior to 1.22.3 (free) and 2.22.3 (premium) that fails to verify user permissions when accessing backup nonce identifiers. An authenticated attacker with minimal privileges, such as a subscriber account, can exploit this vulnerability to download the most recent site and database backups, potentially exposing sensitive system information. The vulnerability exists in the heartbeat function and allows attackers to discover paths to backup files without proper capability checks.
Based on public CVE data (MITRE/NVD).