CVE-2023-6553: critical vulnerability in inisev BackupBliss – Backup & Migration with…
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
Published · Updated
100Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 9.8epss 98%
from disclosure to weapon0 days
Published on NVDDec 15
1st PoCDec 13
metasploitDec 11
VulnCheck+1d
exploitation probability
98%top 1% of all CVEs
observed exploitation
yesVulnCheck
15 public exploit(s)
The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the values passed to an include, and subsequently leverage that to achieve remote code execution. This makes it possible for unauthenticated attackers to easily execute code on the server.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
inisev · BackupBliss – Backup & Migration with Free Cloud Storagepublic PoCs found — 15
exploitdbwww.exploit-db.com/exploits/52486unverifiedgithubgithub.com/Chocapikk/CVE-2023-6553★ 86githubgithub.com/motikan2010/CVE-2023-6553-PoC★ 4githubgithub.com/0x00phantom-hat/CVE-2023-6553-RCE-Exploit★ 2githubgithub.com/joaoaugustom/WordPress_Backup_Migration-RCE_Unauthenticated★ 0githubgithub.com/Dungsocool/CVE-2023-6553★ 0githubgithub.com/Harshit-Mashru/CVE-2023-6553★ 0githubgithub.com/cc3305/CVE-2023-6553★ 0vulncheckvulncheck.com/xdb/71f94fe09c5bunverifiedcve_referencepacketstormsecurity.com/files/176638/WordPress-Backup-Migration-1.3.7-Remote-Command-Execution.htmlunverifiedvulncheckvulncheck.com/xdb/e6b3a983d3b2unverifiedvulncheckvulncheck.com/xdb/e6fdf716d949unverifiedvulncheckvulncheck.com/xdb/d01407f9af85unverifiedvulncheckvulncheck.com/xdb/99deaf52bf21unverifiedvulncheckvulncheck.com/xdb/f25701242e22unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — inisev BackupBliss – Backup & Migration with…
In the same product, most dangerous first.
CVE-2023-7002HIGHBackup Migration <= 1.3.9 - Authenticated (Admin+) OS Command Injection via urlEPSS 30.8%CVE-2023-6266HIGHBackup Migration <= 1.3.6 - Unauthenticated Arbitrary Backup Download to Sensitive Information ExposureEPSS 2.1%CVE-2023-6972CRITICALBackup Migration <= 1.3.9 - Unauthenticated Path Traversal to Arbitrary File DeletionEPSS 1.4%CVE-2024-10932HIGHBackup Migration <= 1.4.6 - Unauthenticated PHP Object Injection via 'recursive_unserialize_replace'EPSS 0.8%CVE-2023-0958MEDIUMInisev Plugins (Various Versions) - Missing Authorization on handle_installation functionEPSS 0.7%CVE-2023-3977MEDIUMInisev Plugins (Various Versions) - Cross-Site Request Forgery on handle_installation functionEPSS 0.6%
References
http://packetstormsecurity.com/files/176638/WordPress-Backup-Migration-1.3.7-Remote-Command-Execution.htmlhttps://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.7/includes/backup-heart.php#L118https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.7/includes/backup-heart.php#L38https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.7/includes/backup-heart.php#L62https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.7/includes/backup-heart.php#L64https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3006541%40backup-backup&new=3006541%40backup-backup&sfp_email=&sfph_mail=https://www.synacktiv.com/en/publications/php-filters-chain-what-is-it-and-how-to-use-ithttps://www.wordfence.com/threat-intel/vulnerabilities/id/3511ba64-56a3-43d7-8ab8-c6e40e3b686e?source=cve