S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-6553 Scanner

CVE-2023-6553 scanner - Remote Code Execution (RCE) vulnerability in The Backup Migration plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-6553
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the values passed to an include, and subsequently leverage that to achieve remote code execution. This makes it possible for unauthenticated attackers to easily execute code on the server.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
BackupBliss – Backup & Migration with Free Cloud Storageby inisev
0
Updated Aug 22, 2026View on NVD →
Detail

The Backup Migration plugin for WordPress is a plugin designed to make backing up and migrating WordPress websites easier. This plugin is useful for website owners who want to move their website to a different hosting provider or to simply have a backup in case of data loss. The plugin allows users to create backups of their WordPress website, which can then be easily migrated to a different server or hosting provider.

However, the Backup Migration plugin for WordPress is vulnerable to Remote Code Execution via the /includes/backup-heart.php file. This CVE-2023-6553 vulnerability allows attackers to execute code on the server by controlling the values passed to an include. This vulnerability is present in all versions of the plugin up to, and including, version 1.3.7.

If this vulnerability is exploited, it can lead to complete compromise of the targeted website. Attackers can easily gain access to sensitive data, such as login credentials, payment information, and personal information of users. They may also use the compromised website to spread malware or launch attacks against other websites and servers.

By using the pro features of the s4e.io platform, website owners can easily and quickly learn about vulnerabilities in their digital assets. This platform provides a comprehensive view of all vulnerabilities present in your website or web application, making it easy to identify and fix any security issues. With the help of this platform, website owners can ensure that their digital assets are always secure and protected from any potential threats.

 

REFERENCES

Solution Advice

To protect against the Backup Migration plugin vulnerability, there are some precautions that website owners can take. The following bullet list provides some tips to keep your website safe from this vulnerability:

  • Update the Backup Migration plugin to the latest version as soon as possible.
  • Use a web application firewall (WAF) to filter out any malicious requests that may exploit this vulnerability.
  • Disable the plugin if it is not necessary for your website to function properly.
  • Use a strong password for your WordPress admin account to prevent unauthorized access.
  • Regularly scan your website for vulnerabilities and apply security patches as needed.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.