Vulnerability Description
The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.3.9 via the 'url' parameter. This vulnerability allows authenticated attackers, with administrator-level permissions and above, to execute arbitrary commands on the host operating system.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Backupbliss | Backup Migration | < 1.4.0 |
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.9/includes/ajaExploit
- https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.9/includes/ajaExploit
- https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.9/includes/ajaExploit
- https://plugins.trac.wordpress.org/changeset/3012745/backup-backupPatch
- https://www.linuxquestions.org/questions/linux-security-4/php-function-exec-enabPatchThird Party Advisory
- https://www.wordfence.com/threat-intel/vulnerabilities/id/cc49db10-988d-42bd-a9cThird Party Advisory
- https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.9/includes/ajaExploit
- https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.9/includes/ajaExploit
- https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.9/includes/ajaExploit
- https://plugins.trac.wordpress.org/changeset/3012745/backup-backupPatch
- https://www.linuxquestions.org/questions/linux-security-4/php-function-exec-enabPatchThird Party Advisory
- https://www.wordfence.com/threat-intel/vulnerabilities/id/cc49db10-988d-42bd-a9cThird Party Advisory
FAQ
What is CVE-2023-7002?
CVE-2023-7002 is a vulnerability with a CVSS score of 7.2 (HIGH). The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.3.9 via the 'url' parameter. This vulnerability allows authenticated attackers,...
How severe is CVE-2023-7002?
CVE-2023-7002 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-7002?
Check the references section above for vendor advisories and patch information. Affected products include: Backupbliss Backup Migration.