Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

Critical UpdraftPlus flaw puts 3 million WordPress sites at risk

byEmre Çıtak
June 11, 2026
in Cybersecurity, News
Home News Cybersecurity
Share on FacebookShare on TwitterShare on LinkedInShare on WhatsAppShare on e-mail
Google Preferred Source

A vulnerability in the UpdraftPlus: WP Backup & Migration Plugin affects more than 3 million WordPress websites, permitting unauthenticated attackers to execute commands as administrators. This flaw allows attackers to upload and activate malicious plugins, leading to potential remote code execution.

The UpdraftPlus Backup & Migration Plugin is widely used for creating backups and migrating WordPress sites. It is currently installed on over 3 million websites. The vulnerability does not require an attacker to log in or possess a WordPress account to exploit it. However, only sites with an active Migrator key or UpdraftCentral key are confirmed to be vulnerable.

All versions up to and including 1.26.4 are affected by the exploit, which resides in the UpdraftPlus_Remote_Communications_V2::wp_loaded function. This vulnerability is classified as an authentication bypass flaw, allowing unauthenticated attackers to circumvent the plugin’s identity verification and gain administrator-level access.

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.

According to security firm Wordfence, the details indicate that insufficient validation of remote communications message formats led to this flaw. This failure allows attackers to forge arbitrary RPC commands, which the plugin would execute as legitimate administrator instructions.

The situation illustrates a critical coding flaw—the authentication controls that are supposed to verify the commands are authentic can be bypassed, effectively leaving a backdoor open to unauthorized actions. The compromised system may enable attackers to install backdoor plugins, which can facilitate data theft, malware addition, or total control of the website.

Wordfence reported a significant risk, noting it blocked 8,172 attempted exploits of this vulnerability in a single day. This figure highlights the active attempts by hackers to take advantage of the flaw, though it does not confirm successful compromises.

UpdraftPlus has released a patch for all affected users to secure their installations. Users are urged to update to version 1.26.5 immediately to mitigate this vulnerability.


Featured image credit

Tags: UpdraftPlus flawwordpress

Related Posts

Instagram adds new feature letting users personalize their feed algorithm

Instagram adds new feature letting users personalize their feed algorithm

June 11, 2026
YouTube brings back direct messages after six-year hiatus

YouTube brings back direct messages after six-year hiatus

June 11, 2026
iOS 27 adds Mac-like recovery mode for iPhone and iPad

iOS 27 adds Mac-like recovery mode for iPhone and iPad

June 11, 2026
Ubisoft to close Winnipeg and Belgrade studios, cutting 380 jobs

Ubisoft to close Winnipeg and Belgrade studios, cutting 380 jobs

June 11, 2026
Windows 11 June update boosts speed, adds AI tools and critical fixes

Windows 11 June update boosts speed, adds AI tools and critical fixes

June 11, 2026
Anthropic apologizes for hidden Fable throttling, pledges transparency

Anthropic apologizes for hidden Fable throttling, pledges transparency

June 11, 2026

LATEST NEWS

Critical UpdraftPlus flaw puts 3 million WordPress sites at risk

Instagram adds new feature letting users personalize their feed algorithm

YouTube brings back direct messages after six-year hiatus

iOS 27 adds Mac-like recovery mode for iPhone and iPad

Ubisoft to close Winnipeg and Belgrade studios, cutting 380 jobs

Windows 11 June update boosts speed, adds AI tools and critical fixes

BEST AI MODELS LEADERBOARD

See the best AI models, ranked by intelligence, benchmark results, speed and token price. Find the most suitable LLMs, Text-to-Image, Image Editing, Text-to-Speech, Text-to-Video and Image-to-Video  artificial intelligence model for your tasks and business.

LATEST TOOLS

Roboto AI

Pickaxe

Pfpmaker

MindPal

Syllaby

ScreenApp

FinanceBrain

GitHub Spark

Hints

VisionStory AI

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI tools
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies to improve your experience. You can choose to accept or reject them. Visit our Privacy Policy.