
Image credit: Search Engine Journal
A critical vulnerability in the UpdraftPlus WordPress plugin has exposed more than 3 million websites globally to unauthenticated remote code execution, cybersecurity firm Wordfence reported Tuesday.
The flaw, an authentication bypass, allows attackers to execute commands as an administrator without needing to log in or possess a WordPress account, potentially leading to full website compromise, Wordfence said.
Wordfence, a company specializing in WordPress security, stated that it blocked 8,172 attacks targeting this specific vulnerability within a single 24-hour period.
The vulnerability impacts WordPress sites utilizing the UpdraftPlus: WP Backup & Migration Plugin in versions up to and including 1.26.4, specifically those with an active Migrator key or UpdraftCentral key.
UpdraftPlus, a widely used plugin for backups and migrations, has released a patch to address the security flaw.
Users of the affected plugin versions are advised to update immediately to version 1.26.5 or newer to secure their websites against potential exploitation, according to security experts.
The authentication bypass nature of the vulnerability means that even sites with strong password policies could be at risk if they have not applied the necessary update, analysts said.
Cybersecurity analysts emphasized the urgency of patching, given the widespread use of the UpdraftPlus plugin across millions of WordPress installations.
The flaw highlights the ongoing challenges in maintaining web security, particularly with third-party plugins that extend the functionality of popular content management systems.
Source: Search Engine Journal
Written by
Saeed Ashif Ahmed
I’m Saeed, the CTO of Rabbit Rank, with over a decade of experience in Blogging and SEO since 2010. Partner with us to ensure your project is handled with quality and expertise.
Keep reading
Related Articles

Apple Integrates Google Gemini AI into Revamped Siri
Apple’s new Siri AI, powered by Google’s Gemini, is set to transform search visibility. This integration will...

GWI: Daily AI Overview Users Seek Deeper Content from Cited Sources
GWI data shows daily AI Overview users click through to cited sources 3.5x more often, seeking deeper content....

US government halts Anthropic AI models over security concerns
The U.S. government ordered Anthropic to suspend access to Fable 5 and Mythos 5 AI models due to national secu...