Back

HIGH

Backup Migration <= 1.3.9 - Authenticated (Admin+) OS Command Injection via url

Published Dec 23, 2023

Description

The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.3.9 via the 'url' parameter. This vulnerability allows authenticated attackers, with administrator-level permissions and above, to execute arbitrary commands on the host operating system.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published Dec 23, 2023
Updated Apr 8, 2026
Reserved Dec 20, 2023
CISA Vulnrichment
Updated Jan 3, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a