Impact
The vulnerability is a missing CSRF check on the backup restoration endpoint in the UpdraftPlus WordPress plugin before version 1.26.7. Because authenticated administrators can trigger the restore action without a valid anti‑CSRF token, an attacker can send a crafted link that causes a logged‑in admin to restore an earlier backup. This operation overwrites the current database and files, effectively compromising the integrity of the site and potentially restoring deleted content or reverting recent updates.
Affected Systems
The affected product is the UpdraftPlus: WP Backup & Migration Plugin for WordPress. All deployments using a version prior to 1.26.7 are vulnerable. Plugin users can identify the vulnerability by checking the installed plugin version through the WordPress admin panel or by inspecting the plugin's readme file, which lists the current release.
Risk and Exploitability
The lack of CSRF protection means that any authenticated administrator can be tricked into performing a restoration by clicking a malicious link. Exploitation requires only that the victim be logged into the WordPress site, making the attack relatively easy to launch. No additional credentials or external network access are needed. The EPSS score is < 1%, indicating a low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, but the potential for site‑wide data corruption remains high. Attackers could use social engineering or phishing to deliver the crafted link to administrators.
OpenCVE Enrichment