CVE-2021-24155: Backup Guard < 1.6.0 - Authenticated Arbitrary File Upload
Published Apr 5, 2021
·Updated
The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported files are of the SGBP format and extension, allowing high privilege users (admin+) to upload arbitrary files, including PHP ones, leading to RCE.
Affected Software
1 affected component
Backup-guard Backup Guard Wordpress<1.6.0
Event History
Apr 5, 2021
CVE Published
via MITRE·06:27 PM
Data Sourced
via MITRE·06:27 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-24155?
CVE-2021-24155 is considered a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2021-24155?
To fix CVE-2021-24155, update the Backup Guard WordPress plugin to version 1.6.0 or later.
3
Who is affected by CVE-2021-24155?
CVE-2021-24155 affects users of the Backup Guard WordPress plugin versions prior to 1.6.0.
4
What type of vulnerability is CVE-2021-24155?
CVE-2021-24155 is a remote code execution vulnerability due to improper file handling.
5
What could an attacker achieve by exploiting CVE-2021-24155?
An attacker could upload arbitrary files, including PHP scripts, allowing them to execute code on the server.