Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
100Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 9.8epss 98%
from disclosure to weapon0 days
Published on NVDDec 15
1st PoCDec 13
metasploitDec 11
VulnCheck+1d
exploitation probability
98%top 1% of all CVEs
observed exploitation
yesVulnCheck
13 public exploit(s)
The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the values passed to an include, and subsequently leverage that to achieve remote code execution. This makes it possible for unauthenticated attackers to easily execute code on the server.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
inisev · BackupBliss – Backup & Migration with Free Cloud Storagepublic PoCs found — 13
exploitdbwww.exploit-db.com/exploits/52486unverifiedgithubgithub.com/Chocapikk/CVE-2023-6553★ 86githubgithub.com/motikan2010/CVE-2023-6553-PoC★ 4githubgithub.com/0x00phantom-hat/CVE-2023-6553-RCE-Exploit★ 2githubgithub.com/cc3305/CVE-2023-6553★ 0githubgithub.com/joaoaugustom/WordPress_Backup_Migration-RCE_Unauthenticated★ 0githubgithub.com/Harshit-Mashru/CVE-2023-6553★ 0vulncheckvulncheck.com/xdb/e6b3a983d3b2unverifiedvulncheckvulncheck.com/xdb/e6fdf716d949unverifiedvulncheckvulncheck.com/xdb/d01407f9af85unverifiedvulncheckvulncheck.com/xdb/99deaf52bf21unverifiedcve_referencepacketstormsecurity.com/files/176638/WordPress-Backup-Migration-1.3.7-Remote-Command-Execution.htmlunverifiedvulncheckvulncheck.com/xdb/71f94fe09c5bunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/176638/WordPress-Backup-Migration-1.3.7-Remote-Command-Execution.htmlhttps://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.7/includes/backup-heart.php#L118https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.7/includes/backup-heart.php#L38https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.7/includes/backup-heart.php#L62https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.7/includes/backup-heart.php#L64https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3006541%40backup-backup&new=3006541%40backup-backup&sfp_email=&sfph_mail=https://www.synacktiv.com/en/publications/php-filters-chain-what-is-it-and-how-to-use-ithttps://www.wordfence.com/threat-intel/vulnerabilities/id/3511ba64-56a3-43d7-8ab8-c6e40e3b686e?source=cve