PricingCase studies Login Start trial
Plugin Icon

UpdraftPlus

David Anderson / Team Updraft

Developer

1.25.9

Latest version

3,000,000

Installations

No date

Last updated

WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
    VulnerabilitiesSecurity Contributors

Vulnerability history

0 present
14 fixed
8 Mitigation rules
  • WordPress UpdraftPlus - Backup/Restore plugin <= 1.24.12 - Reflected Cross-Site Scripting vulnerability
    <= 1.24.12
    Jan 15, 2025
  • PHP Object Injection vulnerability
    <= 1.24.11
    Jan 6, 2025
  • Cross-Site Request Forgery to Google Drive Storage Update vulnerability
    <= 1.23.10
    Nov 7, 2023
  • CSRF lead to wp-admin Site Wide XSS vulnerability
    <= 1.23.3
    May 18, 2023
  • Broken Access Control Vulnerability
    1.22.14-1.23.2
    Mar 16, 2023
  • Broken Access Control Vulnerability
    2.22.14-2.23.2
    Mar 16, 2023
  • Information Disclosure
    <= 1.22.24
    Mar 9, 2023
  • Reflected Cross-Site Scripting (XSS) vulnerability
    <= 1.22.8
    Mar 10, 2022
  • Arbitrary Backup Downloads vulnerability
    <= 1.22.1
    Feb 17, 2022
  • Reflected Cross-Site Scripting (XSS) vulnerability
    <= 1.16.66
    Dec 28, 2021
  • Reflected Cross-Site Scripting (XSS) vulnerability
    <= 1.16.65
    Dec 6, 2021
  • Local File Inclusion (LFI) vulnerability
    <= 1.16.58
    Jul 12, 2021
  • Cross Site Scripting
    <= 1.9.6.3
    Apr 20, 2015
  • Privilege Escalation
    <= 1.9.50
    Feb 3, 2015

Vulnerability mitigation

  • Pricing
  • Application security (SCA)
  • RapidMitigate New
  • Threat Intelligence (API)
  • VS Monarx
  • VS Imunify360
  • VS Wordfence
  • Documentation
  • Service status
  • Log in

Code security

  • Managed VDP New
  • Active VDP directory 1,098
  • Security auditing
  • Compliance (CRA) New
  • Log in New

Bug bounty

  • Bug bounty
  • Leaderboard
  • Guidelines
  • Learn New
  • Report
  • Discord
  • Log in New

Use cases

  • Web developers
  • Webhosts New
  • Software vendors
  • WordPress
  • WooCommerce

Resources

  • Vulnerability database
  • Whitepaper 2025 New
  • Articles
  • Case studies New
  • Webinars New
  • Vulnerability statistics

Patchstack

  • About
  • Careers
  • Merch store
  • Media kit
  • LinkedIn
  • Facebook
  • X
© 2025 Patchstack
DPA
Privacy Policy
Accessibility
Terms & Conditions
EU Flag