S4E just found a critical-severity finding from cve-2022-27924 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Aug 30, 2026

CVE-2024-56064 Scanner

CVE-2024-56064 Scanner - Remote Code Execution vulnerability in WP SuperBackup

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.1k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-56064
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

Unrestricted Upload of File with Dangerous Type vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup allows Upload a Web Shell to a Web Server.This issue affects WP SuperBackup: from n/a through <= 2.3.3.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
WP SuperBackupby azzaroco
0
Updated Sep 10, 2026View on NVD →
Detail

The WP SuperBackup plugin is widely used by WordPress sites for backup and migration purposes. Developed by azzaroco, it serves to streamline processes related to site data management and restoration. Website administrators utilize it to ensure regular backups, enabling swift restorations in the case of data loss or corruption. Its popularity among WordPress users stems from its versatility and comprehensive feature set designed to safeguard site content and facilitate migrations. The plugin is particularly beneficial for businesses and bloggers who require reliable data back up and transfer capabilities across various stages of website management. As a critical component of website maintenance, its integrity and security are paramount to users.

The vulnerability in this context involves unauthorized file uploads due to insufficient validation and user permission checks. Exploiting the 'ibk_restore_migrate_check()' function, attackers can upload arbitrary PHP files. This flaw allows unauthenticated attackers to achieve Remote Code Execution (RCE) on affected WordPress servers. The absence of robust validation mechanisms within the plugin's upload functionality leads to significant security risks. By leveraging this flaw, attackers can incapacitate the plugin's security defenses. Such vulnerabilities highlight the need for rigorous security protocols within plugins handling sensitive operations.

The WP SuperBackup plugin falls short in file type validation and lacks a capability check in its ibk_restore_migrate_check()' function. The file upload mechanism does not adequately restrict file types, permitting the upload of malicious PHP scripts. The end point, '/wp-admin/admin.php?page=ibk_admin&tab=restore', becomes a vector for potential exploits. The 'upload_file' parameter specifically is vulnerable, enabling malicious actors to insert harmful code. Uploaded files are stored within '/wp-content/uploads/isnapshots/', where they can be executed. The template checks for successful file uploads by querying specific markers within the uploaded content.

When this vulnerability is exploited, the impact can range from unauthorized server access to total site compromise. Remote Code Execution (RCE) can lead to unauthorized shell access, allowing attackers to manipulate server files and data. Such actions encompass credential theft and backdoor installations, which permit persistent control over the server. The integrity of affected sites is seriously compromised, putting user data and site reputation at risk. Exploitation could potentially result in prolonged unauthorized access and control over server resources, necessitating immediate remediation. This vulnerability emphasizes the importance of secure coding practices and regular security audits.

REFERENCES

Solution Advice
  • Update the WP SuperBackup plugin to version 2.4 or later to patch the vulnerability.
  • Regularly audit and monitor plugins for secure functionality and exploit prevention.
  • Implement stringent file type validation on upload functionalities.
  • Employ robust security plugins for automatic threat detection and mitigation.
  • Ensure frequent backups and server security audits to prevent unauthorized access should an exploit occur.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-56064 Scanner - Remote Code Execution vulnerability in WP SuperBackup | S4E