Executive brief
UpdraftPlus is a popular WordPress plugin used to back up and migrate WordPress sites. The plugin before version 1.26.7 lacks CSRF (cross-site request forgery) protection on backup restoration actions, allowing an attacker to trick a logged-in administrator into restoring an old backup via a malicious link, which would roll back the site's database and files to an earlier state, causing loss of recent content and changes.
Technical details
The vulnerability is a cross-site request forgery (CWE-352) in UpdraftPlus's backup restoration action. The plugin fails to validate WordPress nonces before processing restore requests, allowing an unauthenticated attacker to craft a malicious link that, when clicked by a logged-in administrator, triggers a backup restore without additional confirmation. The attack requires the victim to be logged in with administrator or super-admin privileges and requires that a backup already exists on the target site. An attacker can specify which backup to restore and which site components (database, plugins, themes, uploads) to roll back. The vulnerability has been fixed in version 1.26.7.
Affected products
- UpdraftPlus UpdraftPlus: WP Backup & Migration Plugin before 1.26.7
Timeline
- 2026-08-25: disclosed
- 2026-08-27: patched: Fixed in version 1.26.7