VYPR
Medium severity6.5NVD Advisory· Published Feb 17, 2022· Updated Jun 17, 2026

CVE-2022-0633

CVE-2022-0633

Description

The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download the most recent site & database backup.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • cpe:2.3:a:updraftplus:updraftplus:*:*:*:*:free:wordpress:*:*+ 2 more
    • cpe:2.3:a:updraftplus:updraftplus:*:*:*:*:free:wordpress:*:*range: <1.22.3
    • cpe:2.3:a:updraftplus:updraftplus:*:*:*:*:premium:wordpress:*:*range: <2.22.3
    • (no CPE)range: <1.22.3 (Free), <2.22.3 (Premium)
  • Range: <1.22.3 (Free), <2.22.3 (Premium)
  • UpdraftPlus/UpdraftPlus WordPress Backup Plugin (Free)v5
    Range: 1.22.3
  • UpdraftPlus/UpdraftPlus WordPress Backup Plugin (Premium)v5
    Range: 2.22.3

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.