
Image credit: Search Engine Journal
A critical vulnerability in the UpdraftPlus WordPress plugin has exposed more than 3 million websites globally to unauthenticated remote code execution, cybersecurity firm Wordfence reported Tuesday.
The flaw, an authentication bypass, allows attackers to execute commands as an administrator without needing to log in or possess a WordPress account, potentially leading to full website compromise, Wordfence said.
Wordfence, a company specializing in WordPress security, stated that it blocked 8,172 attacks targeting this specific vulnerability within a single 24-hour period.
The vulnerability impacts WordPress sites utilizing the UpdraftPlus: WP Backup & Migration Plugin in versions up to and including 1.26.4, specifically those with an active Migrator key or UpdraftCentral key.
UpdraftPlus, a widely used plugin for backups and migrations, has released a patch to address the security flaw.
Users of the affected plugin versions are advised to update immediately to version 1.26.5 or newer to secure their websites against potential exploitation, according to security experts.
The authentication bypass nature of the vulnerability means that even sites with strong password policies could be at risk if they have not applied the necessary update, analysts said.
Cybersecurity analysts emphasized the urgency of patching, given the widespread use of the UpdraftPlus plugin across millions of WordPress installations.
The flaw highlights the ongoing challenges in maintaining web security, particularly with third-party plugins that extend the functionality of popular content management systems.
Source: Search Engine Journal
Written by
Saeed Ashif Ahmed
I’m Saeed, the CTO of Rabbit Rank, with over a decade of experience in Blogging and SEO since 2010. Partner with us to ensure your project is handled with quality and expertise.
Keep reading
Related Articles

X Removes 42,000 AI Chatbot Accounts in Spam Combat
X’s head of product, Nikita Bier, live-tweeted the company’s battle against AI chatbot spam, revealing motivat...

Cloudflare, AWS Launch Pay-Per-Crawl Systems for AI Bots
Cloudflare and AWS introduce pay-per-crawl for AI bots using HTTP 402, empowering publishers to control and mo...

Google report shows AI queries diverge from daily life activities
Google’s AI & Economy ATLAS report shows a stark contrast between what Americans ask AI about and their daily...