CVE-2023-6972: Backup Migration <= 1.3.9 - Unauthenticated Path Traversal to Arbitrary File Deletion
The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 via the 'content-backups' and 'content-name', 'content-manifest', or 'content-bmitmp' and 'content-identy' HTTP headers. This makes it possible for unauthenticated attackers to delete arbitrary files, including the wp-config.php file, which can make site takeover and remote code execution possible.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6972?
CVE-2023-6972 is classified as a high severity vulnerability due to its ability to allow unauthenticated attackers to exploit path traversal.
How do I fix CVE-2023-6972?
To fix CVE-2023-6972, update the Backup Migration plugin to version 1.4.0 or later.
What versions of the Backup Migration plugin are affected by CVE-2023-6972?
All versions of the Backup Migration plugin up to and including 1.3.9 are affected by CVE-2023-6972.
Can CVE-2023-6972 be exploited without authentication?
Yes, CVE-2023-6972 can be exploited by unauthenticated attackers.
What does the path traversal vulnerability in CVE-2023-6972 allow an attacker to do?
The path traversal vulnerability in CVE-2023-6972 allows attackers to potentially delete files from the server.