← Vulnerability feed

Vulnerability record · CVE-2021-25089 · published 1 February 2022

CVE-2021-25089: Updraftplus cross-site scripting vulnerability

Updraftplus · Updraftplus

The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.69 does not sanitise and escape the updraft_restore parameter before outputting it back in the Restore page, leading to a Reflected Cross-Site Scripting

6.1 CVSS 3.1 Medium EPSS 0.80% · top 45.1% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
0.80%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.69 does not sanitise and escape the updraft_restore parameter before outputting it back in the Restore page, leading to a Reflected Cross-Site Scripting

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-25089 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2017-16870Updraftplus server-side request forgery (ssrf) vulnerabilityThe UpdraftPlus plugin through 1.13.12 for WordPress has SSRF in the updraft_ajax_handler function in /wp-content/plugins/updraftplus/admin.php via a…EPSS 0.96%8.1CVE-2017-16871Updraftplus code injection vulnerabilityThe UpdraftPlus plugin through 1.13.12 for WordPress allows remote PHP code execution because the plupload_action function in /wp-content/plugins/upd…EPSS 1.6%6.5CVE-2022-0633Updraftplus incorrect authorization vulnerabilityThe UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a…EPSS 2.1%6.1CVE-2023-32960Updraftplus cross-site request forgery vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in UpdraftPlus.Com, DavidAnderson UpdraftPlus WordPress Backup Plugin <= 1.23.3 versions leads to sit…EPSS 0.21%6.1CVE-2022-0864Updraftplus cross-site scripting vulnerabilityThe UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval parameter before outputting …EPSS 7.4%6.1CVE-2021-25022Updraftplus cross-site scripting vulnerabilityThe UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.66 does not sanitise and escape the backup_timestamp and job_id parameter before…EPSS 1.1%6.1CVE-2017-18593Updraftplus cross-site scripting vulnerabilityThe updraftplus plugin before 1.13.5 for WordPress has XSS in rare cases where an attacker controls a string logged to a log file.EPSS 0.92%6.1CVE-2015-9360Updraftplus cross-site scripting vulnerabilityThe updraftplus plugin before 1.9.64 for WordPress has XSS via add_query_arg() and remove_query_arg().EPSS 0.95%

Source: NIST National Vulnerability Database (record CVE-2021-25089), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.