UpdraftPlus security vulnerability - WordPress Security Newsletter
Hello,
this afternoon, UpdraftPlus 1.22.3 released an important security update for the most popular WordPress backup plugin (3+ million active installations).
I use it myself on all client sites and as part of hack cleanup work - so I think it is important to inform you quickly here.
1.22.3 – 15/FEB/2022
SECURITY: Thanks to Marc-Alexandre Montpas of Automattic for this report. All versions of UpdraftPlus from March 2019 onwards have contained a vulnerability caused by a missing permissions-level check. If your site does not have non-admin users, or if your non-admin users are all trusted (and your site does not allow users to sign up themselves), then you are not vulnerable (but we always recommend updating to the latest version in any case). Fuller details will be released after a short time interval allowing users to update.
I have brought my maintenance clients up to date immediately.
General tips for securing WordPress as effectively as possible can be found in my blog.
NinjaFirewall protects and informs you about vulnerabilities like this at the same time.
The newsletter was sent to all customers who were previously entered in the newsletter system. Many have since switched from Joomla to WordPress - Joomla 4.1 is very promising! :-)
If you no longer wish to receive newsletters from me, please unsubscribe using the links below.
Kind regards
Pascal Lohmann
website-bereinigung.de
Start live chat
Schedule a call
{modify}Manage subscriptions{/modify}
{unsubscribe}Unsubscribe from the WordPress update newsletter{/unsubscribe}
