Critical Unauthenticated Authentication Bypass Vulnerability Patched in UpdraftPlus WordPress Plugin
A critical unauthenticated authentication bypass vulnerability in UpdraftPlus was patched in June 2026. This flaw allows attackers to execute arbitrary commands as administrators on sites connected to UpdraftCentral, risking full site compromise. Immediate plugin updates and firewall protections are essential.