Vulnerability record · CVE-2023-6553 · published 15 December 2023
CVE-2023-6553: Backup Migration WordPress plugin unauthenticated remote code execution
Backupbliss · Backup Migration
The Backup Migration plugin for WordPress, in versions up to and including 1.3.7, passes attacker-controlled values into an include in /includes/backup-heart.php, allowing code injection. Because the flaw is reachable without authentication, any exposed WordPress site running an affected version can be compromised remotely.
Description
The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the values passed to an include, and subsequently leverage that to achieve remote code execution. This makes it possible for unauthenticated attackers to easily execute code on the server.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote code execution with a CVSS of 9.8 and very high EPSS makes this an urgent patch.
What it is
The Backup Migration plugin for WordPress, in versions up to and including 1.3.7, passes attacker-controlled values into an include in /includes/backup-heart.php, allowing code injection. Because the flaw is reachable without authentication, any exposed WordPress site running an affected version can be compromised remotely.
Impact
An unauthenticated attacker can execute arbitrary code on the server, leading to full site compromise, data theft, or use of the host as a foothold.
Attack surface
Reached over the network via the plugin's backup-heart.php endpoint; the CVSS vector shows no privileges or user interaction required. No authentication is needed.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.97846, 99.9th percentile) and public exploit references exist, indicating active exploitation is likely.
What to do
- Update the Backup Migration plugin to a version later than 1.3.7 immediately.
- If patching is not possible, disable or remove the plugin until it can be updated.
- Restrict access to /wp-content/plugins/backup-backup/includes/backup-heart.php at the web server or WAF.
- Audit the WordPress installation for signs of compromise and rotate credentials and secrets.
- Monitor plugin and WordPress core versions for further advisories.
Detection
- Search web logs for requests to /includes/backup-heart.php, especially with unusual parameters or POST bodies.
- Look for unexpected PHP files or modified files under wp-content and the web root.
- Monitor for outbound connections or new processes spawned by the web server user.
- Review WordPress audit logs for plugin file changes or unexpected admin activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-6553 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-6553), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.