S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24155 Scanner

CVE-2021-24155 scanner - Unrestricted File Upload vulnerability in Backup Guard plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.3k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24155
7.2
CVSS

The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported files are of the SGBP format and extension, allowing high privilege users (admin+) to upload arbitrary files, including PHP ones, leading to RCE.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
WordPress Backup and Migrate Plugin – Backup Guard
AFFECTED< 1.6.0SAFE ✓≥ 1.6.0
Updated Aug 21, 2026View on NVD →
Detail

The Backup Guard plugin for WordPress is a widely-used plugin that enables users to backup and migrate their website data. Installed on over 80,000 websites, this plugin is helpful for protecting data in the event of hacks or loss. It offers users the ability to backup their data and migrate it to different web hosts with ease. The importance of data backup cannot be overstated, making this plugin a valuable asset for WordPress users.

Recently, CVE-2021-24155 vulnerability was discovered in the Backup Guard WordPress plugin, in versions 1.6.0 and prior. This vulnerability is of high concern for WordPress users since it allows high privilege users (admin+) to upload arbitrary files, including PHP ones, leading to RCE. Essentially, this means that malicious actors can upload and execute arbitrary code on vulnerable websites by exploiting the vulnerability, potentially leading to a loss of sensitive data or even a full site takeover.

When exploited, this vulnerability can be devastating for website owners. Malicious actors can leverage this security flaw to compromise a website's integrity, steal user data, or manipulate the site's content. Given the significant risks involved, it is imperative that users take immediate action to secure their websites.

The Backup Guard WordPress plugin has enabled website owners to backup and migrate their data with ease. However, the discovery of the CVE-2021-24155 vulnerability serves as a reminder that even the most trusted plugins can be targeted by malicious actors. At s4e.io, we offer pro features like vulnerability scanning to help website owners stay abreast of security risks and protect their digital assets from harm. With our advanced tools, you can readily detect, assess, and patch potential vulnerabilities, keeping your websites and data safe from the latest threats. Contact us today to learn more about how we can help secure your digital assets.

 

REFERENCES

Solution Advice

There are several precautions that website owners can take to protect against this vulnerability. These include:

  • Upgrade the plugin to the latest version (1.6.1) as soon as possible.
  • Check the Backup Guard plugin settings to ensure that it only accepts backups of the SGBP format and extension.
  • Employ a web application firewall (WAF) to monitor incoming web traffic and block suspicious activity.
  • Regularly perform scans and security audits to detect and mitigate vulnerabilities.
  • Implement strong authentication measures, such as two-factor authentication (2FA), to reduce the risk of unauthorized access to the site.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-24155 scanner - Unrestricted File Upload vulnerability in Backup Guard plugin for WordPress | S4E