Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-32960: WordPress UpdraftPlus plugin <= 1.23.3 - CSRF lead to wp-admin Site Wide XSS vulnerability - Patchstack

Cross-Site Request Forgery (CSRF) vulnerability in UpdraftPlus.Com, DavidAnderson UpdraftPlus WordPress Backup Plugin <= 1.23.3 versions leads to sitewide Cross-Site Scripting (XSS).

CVE
#xss#csrf#vulnerability#wordpress#auth

Solution

Fixed

Update the WordPress UpdraftPlus plugin to the latest available version (at least 1.23.4).

Found this useful? Thank Rafie Muhammad (Patchstack) for reporting this vulnerability. Buy a coffee ☕

Rafie Muhammad (Patchstack) discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress UpdraftPlus Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 1.23.4.

Other vulnerabilities in this plugin

0 present

11 patched

View all

Report to Patchstack Alliance bounty platform and earn monthly cash prizes.

Learn more

Related news

Critical Security Flaw in Social Login Plugin for WordPress Exposes Users' Accounts

A critical security flaw has been disclosed in miniOrange's Social Login and Register plugin for WordPress that could enable a malicious actor to log in as any user-provided information about email address is already known. Tracked as CVE-2023-2982 (CVSS score: 9.8), the authentication bypass flaw impacts all versions of the plugin, including and prior to 7.6.4. It was addressed on June 14, 2023

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907