CVE-2023-7002: Backup Migration <= 1.3.9 - Authenticated (Admin+) OS Command Injection via url
The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.3.9 via the 'url' parameter. This vulnerability allows authenticated attackers, with administrator-level permissions and above, to execute arbitrary commands on the host operating system.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7002?
CVE-2023-7002 is considered a high severity vulnerability due to its ability to allow authenticated attackers to execute arbitrary commands on the host.
How do I fix CVE-2023-7002?
To fix CVE-2023-7002, update the Backup Migration plugin to version 1.4.0 or later.
Who is affected by CVE-2023-7002?
CVE-2023-7002 affects users of the Backup Migration plugin for WordPress running versions up to and including 1.3.9.
What causes CVE-2023-7002?
CVE-2023-7002 is caused by a lack of proper input validation in the 'url' parameter, leading to OS Command Injection risks.
What are the potential impacts of CVE-2023-7002?
The potential impacts of CVE-2023-7002 include unauthorized command execution by attackers with administrator-level permissions, which can compromise the host system.