CVE-2023-6553 is a critical Remote Code Execution (RCE) vulnerability affecting all versions up to 1.3.7 of the Backup Migration plugin for WordPress, impacting approximately 90,000 sites. With a CVSS score of 9.8, it allows unauthenticated attackers to easily execute arbitrary code on the server due to controllable values passed to an include function. This vulnerability is actively exploited, with publicly available Metasploit modules and Nuclei templates, and has garnered significant community discussion and media coverage, indicating widespread awareness and potential for active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.3.7CPE matchmatch criteria | cpe:2.3:a:backupbliss:backup_migration:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.