CVE-2023-5982
The UpdraftPlus backup plugin for WordPress through version 1.23.10 contains a cross-site request forgery vulnerability in its Google Drive authentication handler that fails to properly verify nonce tokens and validate the instance identifier. An attacker can exploit this flaw by crafting a malicious request that, when clicked by an administrator, modifies the Google Drive destination used for storing backups. Successfully exploiting this vulnerability would allow the attacker to redirect backup files to an attacker-controlled account, potentially exposing sensitive site data.
Based on public CVE data (MITRE/NVD).