Critical Security Flaw in UpdraftPlus Plugin – Immediate Update Required

A critical unauthenticated authentication bypass vulnerability was discovered in the UpdraftPlus plugin, which has over 3 million active installations. This flaw allows attackers to execute arbitrary commands as the connected administrator, potentially leading to complete site compromise. Users are urged to update to the latest version immediately to avoid exploitation.

Details of the Vulnerability

The vulnerability affects UpdraftPlus versions up to 1.26.4 (free) and 2.26.5 (premium). It is exploitable on sites connected to UpdraftCentral, allowing attackers to run Remote Procedure Calls (RPC) without authentication. This could enable them to upload and activate malicious plugins, leading to full control over the site.

Response from UpdraftPlus Team

The UpdraftPlus team was notified on June 3, 2026, and promptly released a patch on June 5, 2026. Users are encouraged to update their plugins to the patched version to mitigate risks associated with this vulnerability.

Recommendations for Users

Website owners should update their UpdraftPlus plugin to the latest version immediately. Additionally, conducting a security audit of the site is advisable to ensure no other vulnerabilities exist.

Frequently Asked Questions

What versions of UpdraftPlus are affected by the vulnerability?

Versions up to 1.26.4 (free) and 2.26.5 (premium) are affected.

When was the vulnerability patched?

The vulnerability was patched on June 5, 2026.

What should I do to protect my site?

Update your UpdraftPlus plugin to the latest version immediately.

What risks does this vulnerability pose?

It allows unauthenticated attackers to run arbitrary commands as the connected administrator, potentially compromising the entire site.