WordPress Plugin Vulnerabilities

UpdraftPlus 1.23.8 - 1.26.7 - Subscriber+ Remote Storage Credential Disclosure via Migration Notice

Description

The plugin does not have any capability check in a routine that outputs its stored remote storage settings into admin pages when the site is left in a particular post-migration state, allowing any authenticated user, such as a subscriber, to retrieve the credentials of the configured backup destinations, such as passwords and secret keys.

Proof of Concept

Affects Plugins

Fixed in 1.26.8
Fixed in 2.26.8.26

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE

Miscellaneous

Original Researcher
Jakub Herman
Submitter
Jakub Herman
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-25 (about 2 days ago)
Added
2026-09-25 (about 1 day ago)
Last Updated
2026-09-25 (about 1 day ago)

Other