S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2022-0864 Scanner

CVE-2022-0864 scanner - Cross-Site Scripting vulnerability in UpdraftPlus

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.4k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0864
6.1
CVSS

The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
UpdraftPlus WordPress Backup Plugin
AFFECTED< 1.22.9SAFE ✓≥ 1.22.9
Updated Aug 22, 2026View on NVD →
Detail

UpdraftPlus is a widely utilized WordPress plugin offering backup and restoration services for websites powered by WordPress. It is designed to protect website data by creating backups of website files and databases, which can be restored in the event of data loss, hacking, or website migration. UpdraftPlus supports scheduled backups, cloud storage options, and is known for its ease of use, making it a popular choice among WordPress administrators and website owners. The plugin is integral for maintaining website security and integrity by ensuring that website data can be quickly recovered without significant downtime or data loss.

Specifically, the vulnerability can be triggered when an administrator accesses a maliciously crafted URL within the UpdraftPlus settings page in the WordPress admin panel. The unsanitized 'updraft_interval' parameter allows for the injection of JavaScript code, which is then executed in the user's browser. This execution can lead to unauthorized actions being performed on behalf of the admin, theft of session tokens, or redirecting the admin to malicious websites. The reflected nature of this XSS vulnerability requires the victim to visit a specially crafted link, which could be distributed via phishing attacks or other social engineering techniques.

Exploitation of this Cross-Site Scripting vulnerability could have several impacts, including the compromise of administrator accounts, theft of sensitive information, manipulation of website content, and spreading of malware to visitors. The ability to execute scripts in the context of the administrator's session could allow attackers to perform any action that the administrator can, potentially leading to a full site compromise. Additionally, the trust and credibility of the affected website could be severely damaged if visitors are subjected to malicious content or phishing attempts.

By joining S4E, users benefit from our comprehensive cybersecurity services, including vulnerability scanning that can detect issues like the XSS vulnerability in UpdraftPlus. Our platform not only identifies vulnerabilities but also provides detailed remediation advice, helping you secure your digital assets effectively. Membership ensures continuous monitoring and protection from emerging threats, reinforcing your website's defenses and preserving the trust of your visitors. With S4E, you gain the tools and insights needed to maintain a secure and resilient online presence.

 

References

Solution Advice
  1. Update the UpdraftPlus plugin to version 1.22.9 or the latest version available to mitigate the XSS vulnerability.
  2. Regularly update all WordPress plugins, themes, and core files to their latest versions to ensure security patches are applied.
  3. Employ a security plugin that provides web application firewall (WAF) capabilities to detect and block XSS and other types of attacks.
  4. Conduct regular security audits and penetration testing to uncover and address vulnerabilities.
  5. Educate users with administrative access about the risks of clicking on untrusted links and the importance of secure browsing practices to prevent exploitation of reflected XSS vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.