• News/
  • https://www.bleepingcomputer.com/news/security/50k-wordpress-sites-exposed-to-rce-attacks-by-critical-bug-in-backup-plugin/

50K WordPress sites exposed to RCE attacks by critical bug in backup plugin

BleepingComputer
·
Sergiu Gatlan
·
Published Dec 11, 2023
·
Updated

A critical severity vulnerability in a WordPress plugin with more than 90,000 installs can let attackers gain remote code execution to fully compromise vulnerable websites. Known as Backup Migration, the plugin helps admins automate site backups to local storage or a Google Drive account. The security bug (tracked as CVE-2023-6553 and rated with a 9.8/10 severity score) was discovered by a team of bug hunters known as Nex Team, who reported it to WordPress security firm Wordfence under a recently launched bug bounty program. It impacts all plugin versions up to and including Backup Migration 1.3.6, and malicious actors can exploit it in low-complexity attacks without user interaction. CVE-2023-6553 allows unauthenticated attackers to take over targeted websites by gaining remote code execution through PHP code injection via the /includes/backup-heart.php file. "This is due to an attacker being able to control the values passed to an include, and subsequently leverage that to achieve remote code execution. This makes it possible for unauthenticated threat actors to easily execute code on the server," Wordfence said on Monday. "By submitting a specially-crafted request, threat-actors can leverage this issue to include arbitrary, malicious PHP code and execute arbitrary commands on the underlying server in the security context of the WordPress instance." In the /includes/backup-heart.php file used by the Backup Migration plugin, an attempt is made to incorporate bypasser.php fr...

Read full article

Affected Software

1 affected component
BackupBliss Backup Migration=1.3.6

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical vulnerability in the Backup Migration plugin for WordPress that exposes around 50,000 sites to remote code execution attacks.

2

What security implications are discussed in the article?

The article highlights how the vulnerability could allow attackers to gain full control over compromised WordPress websites.

3

What products or software are affected by the vulnerability?

The affected product is the Backup Migration plugin by BackupBliss, particularly version 1.3.6.

4

How many WordPress sites are reported to be vulnerable?

Approximately 50,000 WordPress sites are reported to be vulnerable due to this critical bug.

5

What action is recommended for WordPress site administrators?

Site administrators are advised to update the Backup Migration plugin to mitigate the risk of remote code execution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203