peter bassill · operator
$ cve CVE-2023-6553 JSON

CVE-2023-6553 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 97.8% (pctl 100)

Patch early

A public exploit exists.

Description

The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the values passed to an include, and subsequently leverage that to achieve remote code execution. This makes it possible for unauthenticated attackers to easily execute code on the server.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS97.85% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2023-12-15
Last modified2026-06-17

Affected (1)

VendorProduct
backupblissbackup migration

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD