CVE-2023-6553
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the values passed to an include, and subsequently leverage that to achieve remote code execution. This makes it possible for unauthenticated attackers to easily execute code on the server.
El complemento Backup Migration para WordPress es vulnerable a la ejecución remota de código en todas las versiones hasta la 1.3.7 incluida a través del archivo /includes/backup-heart.php. Esto se debe a que un atacante puede controlar los valores pasados a una inclusión y, posteriormente, aprovecharlos para lograr la ejecución remota de código. Esto hace posible que atacantes no autenticados ejecuten código fácilmente en el servidor.
WordPress Backup Migration plugin versions 1.3.7 and below suffer from a remote code execution vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-12-06 CVE Reserved
- 2023-12-11 CVE Published
- 2023-12-27 First Exploit
- 2024-08-02 CVE Updated
- 2024-11-14 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (13)
URL | Date | SRC |
---|---|---|
https://github.com/Chocapikk/CVE-2023-6553 | 2024-02-06 | |
https://github.com/cc3305/CVE-2023-6553 | 2024-07-27 | |
https://github.com/kiddenta/CVE-2023-6553 | 2024-05-11 | |
https://github.com/motikan2010/CVE-2023-6553-PoC | 2023-12-27 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Backupbliss Search vendor "Backupbliss" | Backup Migration Search vendor "Backupbliss" for product "Backup Migration" | <= 1.3.7 Search vendor "Backupbliss" for product "Backup Migration" and version " <= 1.3.7" | wordpress |
Affected
|