← Vulnerability feed

Vulnerability record · CVE-2023-5982 · published 7 November 2023

CVE-2023-5982: Updraftplus cross-site request forgery vulnerability

Updraftplus · Updraftplus

The UpdraftPlus: WordPress Backup & Migration Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.23.10. This is due to a lack of nonce validation and insufficient validation of the instance_id on the 'updraftmethod-googledrive-auth' action used to update Google Drive remote storage location. This makes it possible for unauthenticated attackers to modify the Google Drive location that backups are sent to via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This can make it possible for attackers to receive backups for a site which may contain sensitive information.

5.4 CVSS 3.1 Medium EPSS 0.22% · top 89.0% CWE-352 · Cross-site request forgery
5.4CVSS 3.1 base score
0.22%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

The UpdraftPlus: WordPress Backup & Migration Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.23.10. This is due to a lack of nonce validation and insufficient validation of the instance_id on the 'updraftmethod-googledrive-auth' action used to update Google Drive remote storage location. This makes it possible for unauthenticated attackers to modify the Google Drive location that backups are sent to via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This can make it possible for attackers to receive backups for a site which may contain sensitive information.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-5982 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2017-16870Updraftplus server-side request forgery (ssrf) vulnerabilityThe UpdraftPlus plugin through 1.13.12 for WordPress has SSRF in the updraft_ajax_handler function in /wp-content/plugins/updraftplus/admin.php via a…EPSS 0.96%8.1CVE-2017-16871Updraftplus code injection vulnerabilityThe UpdraftPlus plugin through 1.13.12 for WordPress allows remote PHP code execution because the plupload_action function in /wp-content/plugins/upd…EPSS 1.6%6.5CVE-2022-0633Updraftplus incorrect authorization vulnerabilityThe UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a…EPSS 2.1%6.1CVE-2023-32960Updraftplus cross-site request forgery vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in UpdraftPlus.Com, DavidAnderson UpdraftPlus WordPress Backup Plugin <= 1.23.3 versions leads to sit…EPSS 0.21%6.1CVE-2022-0864Updraftplus cross-site scripting vulnerabilityThe UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval parameter before outputting …EPSS 7.4%6.1CVE-2021-25089Updraftplus cross-site scripting vulnerabilityThe UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.69 does not sanitise and escape the updraft_restore parameter before outputting …EPSS 0.80%6.1CVE-2021-25022Updraftplus cross-site scripting vulnerabilityThe UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.66 does not sanitise and escape the backup_timestamp and job_id parameter before…EPSS 1.1%6.1CVE-2017-18593Updraftplus cross-site scripting vulnerabilityThe updraftplus plugin before 1.13.5 for WordPress has XSS in rare cases where an attacker controls a string logged to a log file.EPSS 0.92%

Source: NIST National Vulnerability Database (record CVE-2023-5982), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.