Vulnerabilities

50K WordPress sites exposed to RCE attacks

0

A critical severity vulnerability in a WordPress plugin with over 90,000 installs can let attackers gain remote code execution to fully compromise vulnerable websites.

The plugin known as Backup Migration, helps admins automate site backups to local storage or a Google Drive account.

The security bug tracked as CVE-2023-6553 and has a 9.8/10 severity score was discovered by a team of bug hunters known as Nex Team, who reported it to WordPress security firm Wordfence under a recently launched bug bounty program.

It impacts all plugin versions up to and including Backup Migration 1.3.6, and malicious actors can exploit it in low-complexity attacks without user interaction.

The vulnerability allows unauthenticated attackers to take over targeted websites by gaining remote code execution through PHP code injection via the /includes/backup-heart.php file.

Wordfence reported the critical security flaw to BackupBliss, the development team behind the Backup Migration plugin, on December 6, for which the developers released a patch hours later.

However, despite the release of the patched Backup Migration 1.3.8 plugin version on the day of the report, almost 50,000 WordPress websites using a vulnerable version still have to be secured.

Admins are strongly advised to secure their websites against potential CVE-2023-6553 attacks.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

US govt agencies breached using Adobe ColdFusion exploit

Previous article

Lazarus hackers target Log4Shell flaw via Telegram bots

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *