QID 731013

Date Published: 2023-12-14

QID 731013: WordPress Plugin Backup Migration Remote Code Execution (RCE) Vulnerability

Backup Migration plugin is all in one solution if you need to migrate your site to another host or just restore the local backup.

CVE-2023-6553: WordPress Plugin Backup Migration prior to 1.3.8 backup-backup is prone to Unauthenticated Remote Code Execution (RCE) Vulnerability.

Affected Versions:
WordPress Plugin Backup Migration prior to 1.3.8

QID Detection Logic:
This unauthenticated detection checks for installed vulnerable version for Backup Migration Plugin using Blind Elephant Fingerprint technique.

Successful exploitation of this vulnerability may allow unauthenticated attackers to easily execute code on the server.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to upgrade to Backup Migration Plugin version 1.3.8 or later to remediate this vulnerability.

    Vendor References

    CVEs related to QID 731013

    Software Advisories
    Advisory ID Software Component Link
    Backup Migration Plugin URL Logo wordpress.org/plugins/backup-backup/#developers