WordPress Plugin Vulnerabilities

UpdraftPlus < 1.26.7 - Backup Restoration via CSRF

Description

The plugin does not have CSRF checks in one of its backup management actions, which could allow attackers to make a logged in admin restore an existing backup, reverting the site's database and files to an earlier state, via a crafted link.

Proof of Concept

Affects Plugins

Fixed in 1.26.7

References

Classification

Miscellaneous

Original Researcher
Jashid Sany
Submitter
Jashid Sany
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-08-25 (about 3 days ago)
Added
2026-08-25 (about 2 days ago)
Last Updated
2026-08-25 (about 2 days ago)

Other