Impact
The vulnerability lies in a missing capability check in UpdraftPlus: WP Backup & Migration Plugin. When a site is left in a specific post‑migration state, any authenticated user—such as a standard subscriber—can access an admin page that outputs the stored remote storage configuration, revealing passwords and secret keys used for backup destinations. This directly exposes sensitive credentials and can lead to further compromise of the backup services and the underlying file system.
Affected Systems
Vendors: UpdraftPlus, plugin versions prior to 1.26.8, and prior to 2.26.8.26 are affected. WordPress sites that have installed these vulnerable plugin releases are at risk.
Risk and Exploitability
The vulnerability can be leveraged by any authenticated user once the migration state issue has been triggered. Because the attacker only needs valid WordPress credentials, the attack vector is considered local with authenticated access. Exploitation does not require elevated privileges, making it readily achievable for regular plugin users. While the EPSS data is not available and the vulnerability is not in the CISA KEV catalog, the potential impact on confidentiality is high, as exposed credentials may grant access to cloud storage or backup services controlled by the site owner.
OpenCVE Enrichment