QID 731013
Date Published: 2023-12-14
QID 731013: WordPress Plugin Backup Migration Remote Code Execution (RCE) Vulnerability
Backup Migration plugin is all in one solution if you need to migrate your site to another host or just restore the local backup.
CVE-2023-6553: WordPress Plugin Backup Migration prior to 1.3.8 backup-backup is prone to Unauthenticated Remote Code Execution (RCE) Vulnerability.
Affected Versions:
WordPress Plugin Backup Migration prior to 1.3.8
QID Detection Logic:
This unauthenticated detection checks for installed vulnerable version for Backup Migration Plugin using Blind Elephant Fingerprint technique.
Successful exploitation of this vulnerability may allow unauthenticated attackers to easily execute code on the server.
Solution
Customers are advised to upgrade to Backup Migration Plugin version 1.3.8 or later to remediate this vulnerability.
Vendor References
- WordPress Backup Migration -
wordpress.org/plugins/backup-backup/#developers
CVEs related to QID 731013
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Backup Migration Plugin |
|