← Vulnerability feed

Vulnerability record · CVE-2017-16870 · published 17 November 2017

CVE-2017-16870: Updraftplus server-side request forgery (ssrf) vulnerability

Updraftplus · Updraftplus

The UpdraftPlus plugin through 1.13.12 for WordPress has SSRF in the updraft_ajax_handler function in /wp-content/plugins/updraftplus/admin.php via an httpget subaction. NOTE: the vendor reports that this does not cross a privilege boundary

8.1 CVSS 3.0 High EPSS 0.96% · top 40.1% CWE-918 · Server-side request forgery (SSRF)
8.1CVSS 3.0 base score, v2 6.8
0.96%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The UpdraftPlus plugin through 1.13.12 for WordPress has SSRF in the updraft_ajax_handler function in /wp-content/plugins/updraftplus/admin.php via an httpget subaction. NOTE: the vendor reports that this does not cross a privilege boundary

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-16870 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2017-16871Updraftplus code injection vulnerabilityThe UpdraftPlus plugin through 1.13.12 for WordPress allows remote PHP code execution because the plupload_action function in /wp-content/plugins/upd…EPSS 1.6%6.5CVE-2022-0633Updraftplus incorrect authorization vulnerabilityThe UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a…EPSS 2.1%6.1CVE-2023-32960Updraftplus cross-site request forgery vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in UpdraftPlus.Com, DavidAnderson UpdraftPlus WordPress Backup Plugin <= 1.23.3 versions leads to sit…EPSS 0.21%6.1CVE-2022-0864Updraftplus cross-site scripting vulnerabilityThe UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval parameter before outputting …EPSS 7.4%6.1CVE-2021-25089Updraftplus cross-site scripting vulnerabilityThe UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.69 does not sanitise and escape the updraft_restore parameter before outputting …EPSS 0.80%6.1CVE-2021-25022Updraftplus cross-site scripting vulnerabilityThe UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.66 does not sanitise and escape the backup_timestamp and job_id parameter before…EPSS 1.1%6.1CVE-2017-18593Updraftplus cross-site scripting vulnerabilityThe updraftplus plugin before 1.13.5 for WordPress has XSS in rare cases where an attacker controls a string logged to a log file.EPSS 0.92%6.1CVE-2015-9360Updraftplus cross-site scripting vulnerabilityThe updraftplus plugin before 1.9.64 for WordPress has XSS via add_query_arg() and remove_query_arg().EPSS 0.95%

Source: NIST National Vulnerability Database (record CVE-2017-16870), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.