CVE-2023-32960
The UpdraftPlus backup and migration plugin for WordPress contains a cross-site request forgery vulnerability in versions up to 1.23.3, stemming from inadequate nonce verification in the action_authenticate_storage function. An unauthenticated attacker could exploit this flaw by crafting a malicious request to inject malicious JavaScript into authentication parameters, which would then execute in an administrator's browser during subsequent interactions. Successful exploitation requires the attacker to deceive a site administrator into performing multiple actions, including re-authenticating the storage connection. The vulnerability was fixed in version 1.23.4.
Based on public CVE data (MITRE/NVD).