CVE-2023-6971: Critical severity backupbliss backup migration vulnerability
The Backup Migration plugin for WordPress is vulnerable to Remote File Inclusion in versions 1.0.8 to 1.3.9 via the 'content-dir' HTTP header. This makes it possible for unauthenticated attackers to include remote files on the server, resulting in code execution. NOTE: Successful exploitation of this vulnerability requires that the target server's php.ini is configured with 'allowurlinclude' set to 'on'. This feature is deprecated as of PHP 7.4 and is disabled by default, but can still be explicitly enabled in later versions of PHP.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6971?
CVE-2023-6971 is considered critical due to the potential for remote code execution.
How do I fix CVE-2023-6971?
To mitigate CVE-2023-6971, update the Backup Migration plugin to version 1.4.0 or later.
Who is affected by CVE-2023-6971?
CVE-2023-6971 affects users of the Backup Migration plugin for WordPress versions 1.0.8 to 1.3.9.
What type of vulnerability is CVE-2023-6971?
CVE-2023-6971 is a Remote File Inclusion (RFI) vulnerability.
Can CVE-2023-6971 be exploited by unauthenticated users?
Yes, CVE-2023-6971 can be exploited by unauthenticated attackers.