WordPress Plugin Vulnerabilities

UpdraftPlus < 1.16.59 - Admin+ Local File Inclusion

Description

The plugin did not validate its updraft_service settings, and using the user supplied value to include the related file, leading to a Local File Inclusion issue

Proof of Concept

Affects Plugins

Fixed in 1.16.59

Classification

Type
LFI
OWASP top 10
CWE

Miscellaneous

Original Researcher
WPScanTeam
Verified
Yes

Timeline

Publicly Published
2021-07-12 (about 4 years ago)
Added
2021-12-27 (about 4 years ago)
Last Updated
2021-12-27 (about 4 years ago)

Other