Close Menu
  • Home
  • Learn
  • Web Hosting
  • Website Optimization
  • Elementor
  • Tech Jobs
  • Consultations NEW
  • More
    • About
    • Contact
    • Artificial Intelligence
    • CDN
    • Deals & Discounts
    • eCommerce
    • Movies & TV Shows
    • MyListing
    • Small Business
    • Themes & Templates
    • Tools
      • Internet Speedtest
      • VPN
    • Voxel
    • VPN
    • Web Hosting Services
    • Web Security
    • WooCommerce
    • WordPress
Tags
Analytics Archive auctions wordpress theme Backups Business business directory ChatGPT city guide classified Code Editors cPanel Crocoblock Deals directory Discord Discounts dokan ecommerce education wordpress theme Featured FTP Generative AI Google Cloud Google DeepMind grocery multivendor learning management system LiteSpeed Cache lms marketplace Matomo multi-vendor Opera PHP Plugin Update responisve shopify theme Sale SEO shop SSH Trending Updates Web Hosting woocommerce wordpress World Backup Day
Facebook X (Twitter) YouTube
Binary Blackboard
  • Home
  • Learn
  • Web Hosting
    LiteSpeed Cache vs WP Rocket

    LiteSpeed Cache vs WP Rocket

    August 3, 2023
    Storage racks aligned in a computer server room.

    Shared Web Hosting: Is It the Right Choice for Your Website?

    June 10, 2023
    Memorial day seal with the word deal next to it

    Memorial Day Weekend Deals

    May 25, 2023
    Woman holding a laptop as she works on web hosting servers

    Crucial Things to Know When Choosing Web Hosting Services

    March 27, 2023
    This is the A2 Hosting logo. It says “A2 Hosting Our Speed Your Success.”

    Switching to cPanel’s Jupiter Theme

    March 27, 2023
  • Website Optimization
    Logo for Elementor

    Automatically Clear Elementor Cache and Regenerate CSS

    July 25, 2023
    Screenshot of a macOS shortcut

    Website Speedtest macOS Shortcuts

    June 24, 2023
    New method accelerates data retrieval in huge databases

    New method accelerates data retrieval in huge databases

    March 15, 2023
    LiteSpeed Cache plugin settings dashboard

    LiteSpeed Cache Settings for Voxel

    March 9, 2023
    Logo for Redis Cache

    Are You Using Redis Cache on Your Website?

    March 8, 2023
  • Elementor
    Logo for Elementor

    Automatically Clear Elementor Cache and Regenerate CSS

    July 25, 2023
    Elementor helpful tips

    Unlock the Full Potential of Elementor with These 10 Advanced Tips

    May 20, 2023
    Logo for Elementor

    Master the Art of Web Design with Elementor Pro

    May 20, 2023
    Elementor CSS Print Method Settings

    What Is CSS Print Method in the Elementor Settings? Which Should I Choose?

    May 18, 2023
    Widgets for the Elementor page builder

    Remove Unused Elementor Widgets

    January 15, 2023
  • Tech Jobs
  • Consultations NEW
  • More
    • About
    • Contact
    • Artificial Intelligence
    • CDN
    • Deals & Discounts
    • eCommerce
    • Movies & TV Shows
    • MyListing
    • Small Business
    • Themes & Templates
    • Tools
      • Internet Speedtest
      • VPN
    • Voxel
    • VPN
    • Web Hosting Services
    • Web Security
    • WooCommerce
    • WordPress
Binary Blackboard
Home»Web Security»UpdraftPlus 1.23.3 / 2.23.3 – important security release
Web Security

UpdraftPlus 1.23.3 / 2.23.3 – important security release

March 16, 20234 Mins Read00
Facebook Twitter Pinterest LinkedIn Email WhatsApp Reddit
UpdraftPlus settings

Short version: A security risk identified in UpdraftPlus has been resolved in 1.23.3 (free version) / 2.23.3 (paid versions); you should update to the latest version straight away, and then all will be well.

Who is vulnerable?
The great majority of sites are not vulnerable (but you should update anyway). If your site has untrusted non-admin users who can sign in to your WordPress back-end (i.e. the “wp-admin” dashboard) and you are using an UpdraftPlus version from 1.22.14 to 1.23.2 (free) or 2.22.14 to 2.23.2 (paid) then given sufficient, advanced technical skills, these users have the capability to gain the powers of admins (or on WordPress multisite installs, super-admins). Updating will immediately close this loophole.

If untrusted people can sign up but cannot reach the WordPress back-end dashboard (i.e. at /wp-admin), then you are also not vulnerable (e.g. if you are using WooCommerce, customers in your shop get a WordPress account, but WooCommerce does not allow them to visit the back-end dashboard).

You are not vulnerable to this problem if your version of UpdraftPlus is not in the above range – but we recommend you update as we only support current plugin versions.

Experience with security issues (with which I have worked for over 20 years in different contexts) shows that even thorough analysis can overlook something. So please, update UpdraftPlus on your website.

How the problem was discovered:
First credit belongs to pluginvulnerabilities.com, who notified us of a missing permissions check in our code. At this stage it was known only to be a harmless omission. We then investigated internally if there were any pathways for this missing check to be leveraged to perform further unauthorised operations, and found that this was in fact the case in the scenarios described above.

When and how the problem was introduced:
The issue was introduced in a release of UpdraftPlus in the second half of 2022, as a result of moving existing code around in order to prepare the way for future improvements in that code. This resulted in code that previously had not been reachable without the appropriate permissions check being accessible without it. All our code changes goes through multiple review before being launched, but in this case, there was a subtlety involved in moving around existing code that led us to overlook the implications of the move. We are reviewing how to not allow this to happen in future.

Is the problem being exploited in the wild?
No, not to our knowledge; we discovered the ultimate possibility internally based on a tip-off from a friendly security researcher. You should, of course, still update immediately.

Can you give me technical details of the exploit?
The exploit requires some work to work out and implement. At this stage it is best that we do not help any would-be attackers with that process.

I am using a paid version of UpdraftPlus, and my licence has expired, or I am vulnerable and do not want to update (any version) – what can I do?
Any one of these will protect you:

  1. Users of paid versions can renew their licence in our shop – you can use the coupon march2023nl until the end of March 2023 for a 50% discount. (You must login to an account that has expired licences on it and make a purchase to renew those licences – otherwise it will not be valid).
  2. Or, install and activate the “hotfix” plugin from this page.
  3. Or, delete any non-admin users whom you do not trust
  4. Or, remove their ability to visit the WordPress dashboard using a free plugin like https://wordpress.org/plugins/remove-dashboard-access-for-non-admins/
  5. Or, de-activate UpdraftPlus.
  6. Or, de-install your version of UpdraftPlus and install the free version instead.

How come my site was already automatically updated to this version?
WordPress and UpdraftPlus both show you a setting allowing you to opt-in to automatic updates when a new plugin version is released. If you turned this on, then this likely performed the update.

Web hosting companies also have the ability to automatically update any plugin on your website, so this is another possibility.

By default, the plugins team at wordpress.org has the ability to automatically push updates to all users of wordpress.org plugins (i.e. free plugins in their directory) if they deem it a good idea. They have done so with this update, and so many wordpress.org users will have received the update already via this mechanism. If you don’t want them to be able to do this, then they have documented how to disable that here.

Once more: we are sorry, and are committed to working hard to prevent this happening again. Thank you for being a user of UpdraftPlus.

David Anderson (founder, lead developer)

Source link

Share. Facebook Twitter Pinterest LinkedIn Email WhatsApp Reddit

Related Posts

Wordpress 6.3 Lionel

WordPress Update 6.3 “Lionel” is out

Programming code of PHP for WordPress

Which PHP Version Should You Use for WordPress in 2023?

LiteSpeed Cache vs WP Rocket

LiteSpeed Cache vs WP Rocket

Leave A Reply Cancel Reply

You must be logged in to post a comment.

Affiliate Envato Wordpress theme banner adEnvato Wordpress theme banner ad
Menu
  • About
  • Contact
  • Developer Tools
  • Deals & Discounts
  • Sitemap
  • Privacy Policy
  • Terms of Service
Tags
Analytics Archive auctions wordpress theme Backups Business business directory ChatGPT city guide classified Code Editors cPanel Crocoblock Deals directory Discord Discounts dokan ecommerce education wordpress theme Featured FTP Generative AI Google Cloud Google DeepMind grocery multivendor learning management system LiteSpeed Cache lms marketplace Matomo multi-vendor Opera PHP Plugin Update responisve shopify theme Sale SEO shop SSH Trending Updates Web Hosting woocommerce wordpress World Backup Day
Facebook X (Twitter) YouTube
  • Privacy Policy
  • Terms of Service
Copyright © 2025 - binaryBlackboard.

Type above and press Enter to search. Press Esc to cancel.