CVE-2021-24155
HIGH NUCLEIBackup Guard < 1.6.0 - Authenticated Arbitrary File Upload via SGBP Import
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2021-24155.
PoCs published by Ron Jost, 0dayNinja, Nguyen Van Khanh, Ron Jost, including Metasploit module exploits/multi/http/wp_plugin_backup_guard_rce.
A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit leverages an authenticated file upload vulnerability in WordPress Plugin Backup Guard < 1.6.0, allowing high-privilege users to upload arbitrary PHP files, leading to remote code execution (RCE). The exploit includes a p0wny shell for post-exploitation interaction.
Description
The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported files are of the SGBP format and extension, allowing high privilege users (admin+) to upload arbitrary files, including PHP ones, leading to RCE.
Exploits (3)
This exploit leverages an authenticated file upload vulnerability in WordPress Plugin Backup Guard < 1.6.0, allowing high-privilege users to upload arbitrary PHP files, leading to remote code execution (RCE). The exploit includes a p0wny shell for post-exploitation interaction.
This is a functional Metasploit module that exploits an arbitrary file upload vulnerability in the WordPress Backup Guard plugin (versions < 1.6.0) to achieve authenticated remote code execution. The exploit uploads a malicious PHP file and triggers it via a crafted HTTP request.
This Metasploit module exploits an arbitrary file upload vulnerability in WordPress Backup Guard plugin versions < 1.6.0, allowing authenticated users to upload a malicious PHP file and execute it, resulting in remote code execution.
Nuclei Templates (1)
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H