← Vulnerability feed

Vulnerability record · CVE-2023-6553 · published 15 December 2023

CVE-2023-6553: Backup Migration WordPress plugin unauthenticated remote code execution

Backupbliss · Backup Migration

The Backup Migration plugin for WordPress, in versions up to and including 1.3.7, passes attacker-controlled values into an include in /includes/backup-heart.php, allowing code injection. Because the flaw is reachable without authentication, any exposed WordPress site running an affected version can be compromised remotely.

9.8 CVSS 3.1 Critical EPSS 98% · top 0.1% CWE-94 · Code injection
9.8CVSS 3.1 base score
98%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
15References
17 Jun 2026Last modified by NVD

Description

The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the values passed to an include, and subsequently leverage that to achieve remote code execution. This makes it possible for unauthenticated attackers to easily execute code on the server.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution with a CVSS of 9.8 and very high EPSS makes this an urgent patch.

What it is

The Backup Migration plugin for WordPress, in versions up to and including 1.3.7, passes attacker-controlled values into an include in /includes/backup-heart.php, allowing code injection. Because the flaw is reachable without authentication, any exposed WordPress site running an affected version can be compromised remotely.

Impact

An unauthenticated attacker can execute arbitrary code on the server, leading to full site compromise, data theft, or use of the host as a foothold.

Attack surface

Reached over the network via the plugin's backup-heart.php endpoint; the CVSS vector shows no privileges or user interaction required. No authentication is needed.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.97846, 99.9th percentile) and public exploit references exist, indicating active exploitation is likely.

What to do

  • Update the Backup Migration plugin to a version later than 1.3.7 immediately.
  • If patching is not possible, disable or remove the plugin until it can be updated.
  • Restrict access to /wp-content/plugins/backup-backup/includes/backup-heart.php at the web server or WAF.
  • Audit the WordPress installation for signs of compromise and rotate credentials and secrets.
  • Monitor plugin and WordPress core versions for further advisories.

Detection

  • Search web logs for requests to /includes/backup-heart.php, especially with unusual parameters or POST bodies.
  • Look for unexpected PHP files or modified files under wp-content and the web root.
  • Monitor for outbound connections or new processes spawned by the web server user.
  • Review WordPress audit logs for plugin file changes or unexpected admin activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.7/includes/backup-heart.php#L118 Patch
https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.7/includes/backup-heart.php#L38 Patch
https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.7/includes/backup-heart.php#L62 Patch
https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.7/includes/backup-heart.php#L64 Patch
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3006541%40backup-backup&new=3006541%40b Patch
https://www.synacktiv.com/en/publications/php-filters-chain-what-is-it-and-how-to-use-it Not Applicable
https://www.wordfence.com/threat-intel/vulnerabilities/id/3511ba64-56a3-43d7-8ab8-c6e40e3b686e?source=cve Third Party Advisory
http://packetstormsecurity.com/files/176638/WordPress-Backup-Migration-1.3.7-Remote-Command-Execution.html
https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.7/includes/backup-heart.php#L118 Patch
https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.7/includes/backup-heart.php#L38 Patch
https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.7/includes/backup-heart.php#L62 Patch
https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.7/includes/backup-heart.php#L64 Patch
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3006541%40backup-backup&new=3006541%40b Patch
https://www.synacktiv.com/en/publications/php-filters-chain-what-is-it-and-how-to-use-it Not Applicable
https://www.wordfence.com/threat-intel/vulnerabilities/id/3511ba64-56a3-43d7-8ab8-c6e40e3b686e?source=cve Third Party Advisory

Track CVE-2023-6553 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-6971Backupbliss backup migration inclusion from untrusted sphere vulnerabilityThe Backup Migration plugin for WordPress is vulnerable to Remote File Inclusion in versions 1.0.8 to 1.3.9 via the 'content-dir' HTTP header. This m…EPSS 6.4%9.8CVE-2023-6972Backupbliss backup migration path traversal vulnerabilityThe Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 via the 'content-backups' and '…EPSS 1.4%7.5CVE-2023-6266Backupbliss backup migration information exposure vulnerabilityThe Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file validation on the BMI_BACKUP…EPSS 2.1%7.5CVE-2023-6271Backupbliss backup migration vulnerabilityThe Backup Migration WordPress plugin before 1.3.6 stores in-progress backups information in easy to find, publicly-accessible files, which may allow…EPSS 0.69%7.2CVE-2023-7002Backupbliss backup migration os command injection vulnerabilityThe Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.3.9 via the 'url' parameter. …EPSS 31%6.5CVE-2023-0958Backupbliss backup migration missing authorization vulnerabilitySeveral plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_instal…EPSS 0.69%5.4CVE-2021-36884Backupbliss backup migration cross-site scripting vulnerabilityAuthenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered in WordPress Backup Migration plugin <= 1.1.5 versions.EPSS 0.57%4.3CVE-2023-3977Backupbliss backup migration cross-site request forgery vulnerabilitySeveral plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce c…EPSS 0.61%

Source: NIST National Vulnerability Database (record CVE-2023-6553), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.