Backup Migration
Vendor:
First CVE: Nov 19, 2021 · Active for 4 years
9
Total CVEs
More Total CVEs than 86% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 59% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Backup Migration over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 19, 2021
4 years ago
Most Recent CVE
Jan 11, 2024
927 days ago
CVE Severity & Scoring
Backup Migration9 CVEs
33%
33%
33%
All CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (77.8%)
Unknown0 (0.0%)
Required2 (22.2%)
Privileges Required
Low2 (22.2%)
High1 (11.1%)
None6 (66.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-6553CRITICAL The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to | Dec 15, 2023 | 9.8 | 93 | NO | YES |
CVE-2023-7002HIGH The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.3.9 via the 'url' parameter. This vulnerability allows auth | Dec 23, 2023 | 7.2 | 44 | NO | NO |
CVE-2023-6266HIGH The Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file validation on the BMI_BACKUP case of the handle_downloading | Jan 11, 2024 | 7.5 | 32 | NO | YES |
CVE-2023-6972CRITICAL The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 via the 'content-backups' and 'content-name', 'content-manifes | Dec 23, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-6971CRITICAL The Backup Migration plugin for WordPress is vulnerable to Remote File Inclusion in versions 1.0.8 to 1.3.9 via the 'content-dir' HTTP header. This makes it possible for unauthenti | Dec 23, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-6271HIGH The Backup Migration WordPress plugin before 1.3.6 stores in-progress backups information in easy to find, publicly-accessible files, which may allow attackers monitoring those to | Jan 1, 2024 | 7.5 | 22 | NO | NO |
CVE-2021-36884MEDIUM Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered in WordPress Backup Migration plugin <= 1.1.5 versions. | Nov 19, 2021 | 5.4 | 20 | NO | NO |
CVE-2023-3977MEDIUM Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation | Jul 28, 2023 | 4.3 | 17 | NO | NO |
CVE-2023-0958MEDIUM Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called | Jul 28, 2023 | 6.5 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
11.1% of CVEs· 97th percentile
Nuclei
2 CVEs
22.2% of CVEs· 98th percentile
ExploitDB
1 CVE
11.1% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Backup Migration
Top CWEs
Versions
No cataloged versions.