← Vulnerability feed

Vulnerability record · CVE-2023-6971 · published 23 December 2023

CVE-2023-6971: Backupbliss backup migration inclusion from untrusted sphere vulnerability

Backupbliss · Backup Migration

The Backup Migration plugin for WordPress is vulnerable to Remote File Inclusion in versions 1.0.8 to 1.3.9 via the 'content-dir' HTTP header. This makes it possible for unauthenticated attackers to include remote files on the server, resulting in code execution. NOTE: Successful exploitation of this vulnerability requires that the target server's php.ini is configured with 'allow_url_include' set to 'on'. This feature is deprecated as of PHP 7.4 and is disabled by default, but can still be explicitly enabled in later versions of PHP.

9.8 CVSS 3.1 Critical EPSS 6.4% · top 6.5% CWE-829 · Inclusion from untrusted sphere
9.8CVSS 3.1 base score
6.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

The Backup Migration plugin for WordPress is vulnerable to Remote File Inclusion in versions 1.0.8 to 1.3.9 via the 'content-dir' HTTP header. This makes it possible for unauthenticated attackers to include remote files on the server, resulting in code execution. NOTE: Successful exploitation of this vulnerability requires that the target server's php.ini is configured with 'allow_url_include' set to 'on'. This feature is deprecated as of PHP 7.4 and is disabled by default, but can still be explicitly enabled in later versions of PHP.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-6971 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-6972Backupbliss backup migration path traversal vulnerabilityThe Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 via the 'content-backups' and '…EPSS 1.4%9.8CVE-2023-6553Backup Migration WordPress plugin unauthenticated remote code executionThe Backup Migration plugin for WordPress, in versions up to and including 1.3.7, passes attacker-controlled values into an include in /includes/back…EPSS 98%analysed7.5CVE-2023-6266Backupbliss backup migration information exposure vulnerabilityThe Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file validation on the BMI_BACKUP…EPSS 2.1%7.5CVE-2023-6271Backupbliss backup migration vulnerabilityThe Backup Migration WordPress plugin before 1.3.6 stores in-progress backups information in easy to find, publicly-accessible files, which may allow…EPSS 0.69%7.2CVE-2023-7002Backupbliss backup migration os command injection vulnerabilityThe Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.3.9 via the 'url' parameter. …EPSS 31%6.5CVE-2023-0958Backupbliss backup migration missing authorization vulnerabilitySeveral plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_instal…EPSS 0.69%5.4CVE-2021-36884Backupbliss backup migration cross-site scripting vulnerabilityAuthenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered in WordPress Backup Migration plugin <= 1.1.5 versions.EPSS 0.57%4.3CVE-2023-3977Backupbliss backup migration cross-site request forgery vulnerabilitySeveral plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce c…EPSS 0.61%

Source: NIST National Vulnerability Database (record CVE-2023-6971), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.