Skip to content

Known CVE

UpdraftPlus < 1.22.9 - Cross-Site Scripting

The plugin does not sanitise and escape the updraft_interval parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.

CVE-2022-0864

Medium2022CVSS 6.1CWE-79

wpscan · cve2022 · xss · authenticated · updraftplus · wp-plugin · wp · wordpress

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website