LIVE NEWS
  • U.S. citizen arrested in China ID’d as Min Zin, Myanmar analyst : NPR
  • SPCX Solana Launch Same Day
  • Who Runs the Ransomware Group ‘The Gentlemen?’ – Krebs on Security
  • S&P 500 made big call on SpaceX IPO. Index investors need to know it
  • For Netanyahu, Reelection Could Hinge on Iran War Outcome
  • I Spent a Wild Day With the ‘Computah’ Guy From TikTok — Come Along
  • Only 1 in 4 F-35s is fully mission capable, GAO finds
  • A popular sunscreen ingredient can finally be sold in the United States
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Artificial Intelligence»Critical UpdraftPlus Flaw Puts 3 Million WordPress Sites At Risk
Artificial Intelligence

Critical UpdraftPlus Flaw Puts 3 Million WordPress Sites At Risk

primereportsBy primereportsJune 12, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Critical UpdraftPlus Flaw Puts 3 Million WordPress Sites At Risk
Share
Facebook Twitter LinkedIn Pinterest Email


Critical UpdraftPlus Flaw Puts 3 Million WordPress Sites At Risk

A vulnerability in the UpdraftPlus: WP Backup & Migration Plugin affects more than 3 million WordPress websites, permitting unauthenticated attackers to execute commands as administrators. This flaw allows attackers to upload and activate malicious plugins, leading to potential remote code execution.

The UpdraftPlus Backup & Migration Plugin is widely used for creating backups and migrating WordPress sites. It is currently installed on over 3 million websites. The vulnerability does not require an attacker to log in or possess a WordPress account to exploit it. However, only sites with an active Migrator key or UpdraftCentral key are confirmed to be vulnerable.

All versions up to and including 1.26.4 are affected by the exploit, which resides in the UpdraftPlus_Remote_Communications_V2::wp_loaded function. This vulnerability is classified as an authentication bypass flaw, allowing unauthenticated attackers to circumvent the plugin’s identity verification and gain administrator-level access.

Stay Ahead of the Curve!

Don’t miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.

According to security firm Wordfence, the details indicate that insufficient validation of remote communications message formats led to this flaw. This failure allows attackers to forge arbitrary RPC commands, which the plugin would execute as legitimate administrator instructions.

The situation illustrates a critical coding flaw—the authentication controls that are supposed to verify the commands are authentic can be bypassed, effectively leaving a backdoor open to unauthorized actions. The compromised system may enable attackers to install backdoor plugins, which can facilitate data theft, malware addition, or total control of the website.

Wordfence reported a significant risk, noting it blocked 8,172 attempted exploits of this vulnerability in a single day. This figure highlights the active attempts by hackers to take advantage of the flaw, though it does not confirm successful compromises.

UpdraftPlus has released a patch for all affected users to secure their installations. Users are urged to update to version 1.26.5 immediately to mitigate this vulnerability.


Featured image credit

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleBBC Inside Science – How do you build an unbuildable tower?
Next Article Kennedy Center board to fight order to remove Trump’s name as deadline looms – The Washington Post
primereports
  • Website

Related Posts

Artificial Intelligence

AWS Tunes Up Graviton5 For Agentic AI, Boosts Bang For The Buck Bigtime

June 12, 2026
Artificial Intelligence

“Don’t just grab random stuff off the internet”: What Chainguard found in 52,000 open-source packages

June 12, 2026
Artificial Intelligence

Buying a school laptop? 4 things I’d consider first (and my top 10 picks)

June 11, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Paxton’s win over Cornyn sets up high-stakes Texas clash with Talarico

May 28, 202616 Views

Global Resources Outlook 2024 | UNEP

December 6, 202510 Views

Texas Democrat Talarico claims voting laws are rigged ahead of Paxton race

May 28, 20269 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Cybersecurity
  • Popular Now
  • Crypto
  • Artificial Intelligence
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • U.S. citizen arrested in China ID’d as Min Zin, Myanmar analyst : NPR
  • SPCX Solana Launch Same Day
  • Who Runs the Ransomware Group ‘The Gentlemen?’ – Krebs on Security
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.