A critical severity vulnerability in a WordPress plugin with over 90,000 installs can let attackers gain remote code execution to fully compromise vulnerable websites.
The plugin known as Backup Migration, helps admins automate site backups to local storage or a Google Drive account.
The security bug tracked as CVE-2023-6553 and has a 9.8/10 severity score was discovered by a team of bug hunters known as Nex Team, who reported it to WordPress security firm Wordfence under a recently launched bug bounty program.
It impacts all plugin versions up to and including Backup Migration 1.3.6, and malicious actors can exploit it in low-complexity attacks without user interaction.
The vulnerability allows unauthenticated attackers to take over targeted websites by gaining remote code execution through PHP code injection via the /includes/backup-heart.php file.
Wordfence reported the critical security flaw to BackupBliss, the development team behind the Backup Migration plugin, on December 6, for which the developers released a patch hours later.
However, despite the release of the patched Backup Migration 1.3.8 plugin version on the day of the report, almost 50,000 WordPress websites using a vulnerable version still have to be secured.
Admins are strongly advised to secure their websites against potential CVE-2023-6553 attacks.

















Comments