[ad_1]
Patches have been issued to contain a “severe” security vulnerability in UpdraftPlus, a WordPress plugin with over three million installations, that can be weaponized to download the site’s private data using an account on the vulnerable sites.
“All versions of UpdraftPlus from March 2019 onwards have contained a vulnerability caused by a missing permissions-level check, allowing untrusted users access to backups,” the maintainers of the plugin said in an advisory published this week.
Security researcher Marc-Alexandre Montpas of Automattic has been credited with discovering and…
More Info