Overview

Over three million WordPress installations were affected by a vulnerability (CVE-2022-0633) in the UpdraftPlus backup plugin. This could be used by logged in users to access the private backups which should be restricted to administrators.

Impact

An unprivileged user could download database backups which include website data, user account information and hashed passwords as well as sensitive configuration files.

Affected Products

Every UpdraftPlus version between 1.16.7 and 1.22.3.

Containment, Mitigations & Remediations

Update the plugin and ensure auto-updates are enabled for quicker automatic remediation in future.

Threat Landscape

There’s no evidence of exploitation in-the-wild.
The exploit could be used to gain read access to the database but not to make changes so it’s not immediately useful for Ransomware attacks. Access to passwords could allow additional access but this would require further effort as they were stored in a hashed format.

Mitre Methodologies

T1212 – Exploitation for Credential Access

Further Information

Severe Vulnerability Fixed In UpdraftPlus 1.22.3

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content