Lucene search

K
wpvulndbWpvulndbWPVDB-ID:3E647712-DEF6-4E15-BA0B-02C57C44265C
HistoryDec 22, 2023 - 12:00 a.m.

Backup Migration < 1.4.0 - Authenticated (Admin+) OS Command Injection via url

2023-12-2200:00:00
wpscan.com
16
wordpress
plugin
os command injection
authenticated
adminηΊ§ permissions

AI Score

7.9

Confidence

High

EPSS

0.002

Percentile

59.8%

Description The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.3.9 via the β€˜url’ parameter. This vulnerability allows authenticated attackers, with administrator-level permissions and above, to execute arbitrary commands on the host operating system.

AI Score

7.9

Confidence

High

EPSS

0.002

Percentile

59.8%

Related for WPVDB-ID:3E647712-DEF6-4E15-BA0B-02C57C44265C