CVE-2023-6553
🔴 Łataj teraz
Wtyczka Backup Migration dla WordPressa umożliwia zdalne wykonanie kodu przez nieautoryzowanych użytkowników.
CVSS
9.8
EPSS
93.3%
Exploit
none
Vendor
backupbliss
Opis źródłowy (NVD)
The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the values passed to an include, and subsequently leverage that to achieve remote code execution. This makes it possible for unauthenticated attackers to easily execute code on the server.
rce
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 93.3% |
| Opublikowano (NVD) | 2023-12-15 11:15:47 UTC |
| Ostatnia modyfikacja (NVD) | 2026-04-08 18:18:37 UTC |
Referencje
- https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.7/includes/backup-heart.php#L118 (security@wordfence.com) [Patch]
- https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.7/includes/backup-heart.php#L38 (security@wordfence.com) [Patch]
- https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.7/includes/backup-heart.php#L62 (security@wordfence.com) [Patch]
- https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.7/includes/backup-heart.php#L64 (security@wordfence.com) [Patch]
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3006541%40backup-backup&new=3006541%40backup-backup&sfp_email=&sfph_mail= (security@wordfence.com) [Patch]
- https://www.synacktiv.com/en/publications/php-filters-chain-what-is-it-and-how-to-use-it (security@wordfence.com) [Not Applicable]
- https://www.wordfence.com/threat-intel/vulnerabilities/id/3511ba64-56a3-43d7-8ab8-c6e40e3b686e?source=cve (security@wordfence.com) [Third Party Advisory]
- http://packetstormsecurity.com/files/176638/WordPress-Backup-Migration-1.3.7-Remote-Command-Execution.html (af854a3a-2127-422b-91ae-364da2661108)