UpdraftPlus 1.26.8: Easier setup and stronger security

Posted Category Company news Topics Releases, UpdraftPlus,

Getting your WordPress backups set up correctly shouldn’t feel complicated, especially when you’re using UpdraftPlus for the first time.

UpdraftPlus 1.26.8 introduces a new onboarding wizard that guides you through the initial setup, helping you configure your backups and get protected with less guesswork.

This release also includes an important security update for sites that have been migrated using UpdraftPlus, alongside fixes that make FTP and WebDAV backups more reliable and several smaller compatibility and usability improvements.

Here’s what’s new.

Get your backups set up with confidence

Section titled Get your backups set up with confidence

When you install a backup plugin for the first time, knowing where to start isn’t always obvious. What should you back up? How often should your backups run? And where should you store them?

The new UpdraftPlus onboarding wizard makes those first steps easier by guiding you through the key settings you need to get started.

Instead of having to find your way around the plugin settings on your own, you’ll be guided through the initial configuration so you can get your backups set up quickly and understand the choices you’re making along the way.

The onboarding wizard is available if your site is running WordPress 6.2 or later and PHP 7.4 or later.

UpdraftPlus onboarding wizard showing backup setup, remote storage and automated backup options

Stronger protection for migrated sites

Section titled Stronger protection for migrated sites

UpdraftPlus 1.26.8 also includes an important security improvement affecting a specific set of sites that have previously been migrated using UpdraftPlus.

The issue could occur when a migrated site continued to use an .htaccess file containing a reference to its old address and the site owner had not acted on the notice to update it. Under a particular combination of circumstances, a logged-in non-administrator user could potentially access some saved remote storage credentials.

This issue has been addressed in UpdraftPlus 1.26.8.

Thanks to Jakub Herman for reporting the issue via WPScan.

As always, we recommend keeping UpdraftPlus up to date so that your site benefits from the latest security improvements and fixes.

We’ve also resolved issues that could affect backups sent to FTP and WebDAV storage.

An FTP error that could cause failures in PHP-FPM environments has been fixed, along with a WebDAV compatibility issue related to newer versions of PCRE2.

We’ve also clarified the message shown when testing a WebDAV connection on a server that doesn’t support chunked uploads, making it easier to understand what’s happening when troubleshooting your remote storage setup.

Helping you prepare for upcoming changes

Section titled Helping you prepare for upcoming changes

UpdraftPlus 1.26.8 also includes new notices to give users more time to prepare for future platform and compatibility changes.

Users of legacy Azure Blob Storage accounts will now see an admin notice about their upcoming retirement.

Sites running PHP versions older than 5.6.1 will also see a notice explaining that features relying on phpseclib, including Dropbox, SFTP/SCP, Database Encryption, UpdraftCentral and Migrator, will require a newer PHP version in a future release.

We’ve also updated text throughout the plugin to reflect our move to teamupdraft.com and made several compatibility and code-quality improvements following Plugin Check validation.

UpdraftPlus 1.26.8 is now available to update from your WordPress dashboard.

Go to Plugins > Installed Plugins and select Update now next to UpdraftPlus.

With a simpler setup experience for new users, an important security fix and improvements to remote backup reliability, we recommend updating to UpdraftPlus 1.26.8 to benefit from the latest improvements.

Get more from your WordPress backups

With UpdraftPlus Premium, you get even more control over how you protect your WordPress site, with incremental backups, automatic backups before updates, more remote storage options and advanced migration tools to make backing up, restoring and moving your site easier.

  • SECURITY: On a site which has been migrated (i.e. moved to a new address using UpdraftPlus’s migration feature), and is using an .htaccess file, and the .htaccess file has not been updated with the new site reference, and where the site owner does not respond to the notice to do so, and where the site has non-admin users who can login to the WP dashboard, and where the site had saved storage login credentials in the UpdraftPlus settings, such a logged-in user could access some of those credentials (e.g. could access FTP, but not Dropbox). Thanks to Jakub Herman for notifying us of this issue (via WPScan).
  • FEATURE: Implemented an onboarding wizard to assist first-time users with plugin configuration (requires WordPress 6.2+ and PHP 7.4+).
  • FIX: Error caused by the FTP wrapper referencing the STDIN constant when configuring the cURL CURLOPT_INFILE option. Since STDIN is only defined under the PHP CLI SAPI, this caused failures in PHP-FPM environments.
  • FIX: WebDAV backup failures caused by a deprecated regular expression escape since PCRE2 version 10.45.
  • TWEAK: The “Tour” functionality has been removed from the UI and deactivated. Its underlying code remains temporarily and will be fully removed in a future release.
  • TWEAK: Added an admin notice to inform users about the upcoming retirement of legacy Azure Blob Storage accounts.
  • TWEAK: Warn sites running PHP older than 5.6.1 that phpseclib-dependent features (Dropbox, SFTP/SCP, Database Encryption, UpdraftCentral, Migrator) will require a newer PHP version in future releases; the dashboard notice is also shown again to users who dismissed the previous version of this notice.
  • TWEAK: Update all text labels to use teamupdraft.com instead of updraftplus.com.
  • TWEAK: Fixed the ‘Bad filename format’ error when uploading small backup files via the UpdraftPlus dashboard on older WordPress versions.
  • TWEAK: Clarifying WebDAV settings test popup when server does not support chunked uploads.
  • TWEAK: Addressed several issues identified during Plugin Check (PCP) validation and improved overall plugin compatibility and code quality.

About the author

Profile Image of the author - Ivan

Ivan Đukić

Ivan is the Product Manager for UpdraftPlus. With a background as a full-stack developer, he’s spent years building custom features, plugins, and tools. Often working side by side with product and marketing teams to bring ideas to life. Comfortable across the full lifecycle, from shaping concepts to QA and support, he found product management to be a natural next step. Today, Ivan focuses on turning complex needs into reliable, user-friendly solutions that help WordPress site owners protect and manage their websites with confidence.

UpdraftPlus

Get every feature and fix ever implemented plus access to future releases by subscribing to UpdraftPlus Premium.

From just $70 for the year.

More stories

Our plugins

Try TeamUpdraft’s full suite of WordPress plugins.

  • UpdraftPlus

    Back up, restore and migrate your WordPress website with UpdraftPlus

  • WP-Optimize

    Speed up and optimize your WordPress website. Cache your site, clean the database and compress images

  • UpdraftCentral

    Centrally manage all your WordPress websites’ plugins, updates, backups, users, pages and posts from one location

  • Burst Statistics

    Privacy-friendly analytics for your WordPress site. Get insights without compromising your visitors’ privacy