HomeSecurityBackup Migration: WordPress plugin vulnerable to critical vulnerability

Backup Migration: WordPress plugin vulnerable to critical vulnerability

A critical vulnerability in the WordPress Backup Migration plugin allows attackers to execute code remotely and completely compromise vulnerable sites.

Backup Migration WordPress plugin

Backup Migration has over 90,000 installations and helps site administrators automate website backups to local storage or a Google Drive.

The vulnerability (CVE-2023-6553), considered critical, was discovered by a group of bug hunters known as Nex Team. The group reported the vulnerability to Wordfence (which deals with WordPress security issues) as part of a bug bounty.

See also: WordPress: POP chain allows RCE attacks – Update immediately!

The vulnerability affects all plugin versions up to Backup Migration 1.3.6 and malicious actors can exploit it in attacks , without requiring user interaction.

CVE-2023-6553 allows unauthenticated attackers to take control of targeted websites via remote code execution (with PHP code injection via the /includes/backup-heart.php file).

“ This is because an attacker is able to inspect the values ​​passed to include and then exploit them to achieve remote code execution. This allows unauthorized threat to easily execute code on the server actors ,” Wordfence said on Monday

“By submitting a specially crafted request, threat actors can exploit this issue to include arbitrary, malicious PHP code and execute commands on the underlying server within the WordPress instance's security context .“.

See also: Fake WordPress security advisory distributes backdoor plugin

In the file /includes/backup-heart.php used by the WordPress plugin Backup Migration, an attempt is made to include bypasser.php from the BMI_INCLUDES (defined by concatenating BMI_ROOT_DIR with the includes string) on ​​line 118.

However, BMI_ROOT_DIR is defined via the content-dir HTTP header found on line 62, thus placing BMI_ROOT_DIR under user control.

Backup Migration: WordPress plugin vulnerable to critical vulnerability

An update was released immediately

Wordfence reported the critical bug to BackupBliss, the development team behind the Backup Migration plugin, on December 6. The developers released an update a few hours later and fixed the issue.

However, despite the release of the patched version of the Backup Migration plugin 1.3.8, thousands of WordPress websites are still using a vulnerable version, almost a week later.

Administrators are advised to protect their websites from potential attacks that could exploit the CVE-2023-6553 vulnerability.

See also: WP Fastest Cache plugin: SQL injection vulnerability puts thousands of WordPress sites at risk

Importance of WordPress protection

Protecting WordPress websites is especially important for many reasons. First, WordPress websites are very popular, which means they are a prime target for cybercriminals. If your website is not protected, significant damage can occur. 

Additionally, an unsecured WordPress site can undermine the trust and credibility you have built with customers . If their data is compromised, they are likely to take legal action against you and switch to other companies. 

Securing your website is also important for maintaining the consistency and credibility of your content. If a hacker breaks into your website and corrupts the content, it can give the impression that you are not doing enough with your website.

In other words, ensuring your WordPress website is secure isn’t just about protecting your data – it’s about maintaining customers , preserving your company’s reputation, and staying on top of the competition.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS