What the vulnerability does
01Description
The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.3.9 via the 'url' parameter. This vulnerability allows authenticated attackers, with administrator-level permissions and above, to execute arbitrary commands on the host operating system.
Explanation of Vulnerability in Simple Terms
02Summary
BackupBliss versions up to 1.3.9 contain an OS command injection vulnerability in a high-privilege function. An authenticated administrator can execute arbitrary system commands on the server by providing malicious input to a backup or migration operation. This allows complete server compromise including data theft, modification, and service disruption.
What an attacker can do
03Attacker Capabilities
Run arbitrary system commands on the server with the privileges of the web server process.
Potential impact on your site
04Site Impact
A compromised admin account can lead to full server takeover, data theft, malware installation, and site defacement.
Conditions required to exploit
05Prerequisites
Attacker must have administrator-level access to the site or plugin settings.
Key dates
06Disclosure timeline
December 23, 2023
CVE published
April 8, 2026
Record updated