Information leakage vulnerability in UpdraftPlus WordPress Backup Plugin 1.22.24

The Updraft Plus plugin for WordPress, used up to version 1.22.24, is vulnerable to information disclosure. Unauthenticated attackers can trigger the creation of a log file that contains system configuration information. If the WordPress configuration does not use the “deny from all” directive, then the attackers can access this log file.

Detected in:

UpdraftPlus WordPress Backup Plugin fixed vulnerable versions: >= * <= 1.22.24
UpdraftPlus: WP Backup & Migration Plugin fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.