CVE-2011-4342

BackWPup < 1.7.1 - Remote Code Execution via wpabs Parameter

Title source: manual
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2011-4342. PoCs published by Sense of Security.

AI-analyzed exploit summary This exploit leverages a local file inclusion vulnerability in the WordPress BackWPup plugin (version 1.6.1) via the 'wpabs' parameter in 'wp_xml_export.php'. The static nonce value '822728c8d9' allows unauthenticated remote code execution through a data URI.

Description

PHP remote file inclusion vulnerability in wp_xml_export.php in the BackWPup plugin before 1.7.2 for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the wpabs parameter.

Exploits (1)

exploitdb WORKING POC
by Sense of Security · textwebappsphp
https://www.exploit-db.com/exploits/17056

This exploit leverages a local file inclusion vulnerability in the WordPress BackWPup plugin (version 1.6.1) via the 'wpabs' parameter in 'wp_xml_export.php'. The static nonce value '822728c8d9' allows unauthenticated remote code execution through a data URI.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: WordPress BackWPup plugin 1.6.1
No auth needed
Prerequisites: WordPress BackWPup plugin 1.6.1 installed · Access to the 'wp_xml_export.php' endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Exploit vdb-entry x_refsource_osvdb
http://www.osvdb.org/71481
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/17056
Exploit, URL Repurposed x_refsource_misc
http://www.senseofsecurity.com.au/advisories/SOS-11-003.pdf
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2011/Mar/328
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43565
Exploit mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/11/22/10
Exploit mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/11/22/7

Scores

EPSS 0.1040
EPSS Percentile 95.1%

Details

CWE
CWE-94
Status published
Products (1)
backwpup/backwpup < 1.7.1
Published Oct 08, 2012
Tracked Since Feb 18, 2026