CVE-2021-24155

HIGH NUCLEI

Backup Guard < 1.6.0 - Authenticated Arbitrary File Upload via SGBP Import

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2021-24155. PoCs published by Ron Jost, 0dayNinja, Nguyen Van Khanh, Ron Jost, including Metasploit module exploits/multi/http/wp_plugin_backup_guard_rce. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit leverages an authenticated file upload vulnerability in WordPress Plugin Backup Guard < 1.6.0, allowing high-privilege users to upload arbitrary PHP files, leading to remote code execution (RCE). The exploit includes a p0wny shell for post-exploitation interaction.

Description

The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported files are of the SGBP format and extension, allowing high privilege users (admin+) to upload arbitrary files, including PHP ones, leading to RCE.

Exploits (3)

exploitdb WORKING POC
by Ron Jost · pythonwebappsphp
https://www.exploit-db.com/exploits/50093

This exploit leverages an authenticated file upload vulnerability in WordPress Plugin Backup Guard < 1.6.0, allowing high-privilege users to upload arbitrary PHP files, leading to remote code execution (RCE). The exploit includes a p0wny shell for post-exploitation interaction.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WordPress Plugin Backup Guard < 1.6.0
Auth required
Prerequisites: Valid WordPress admin credentials · Target running Backup Guard < 1.6.0 · Network access to the WordPress admin panel
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 10 stars
by 0dayNinja · poc
https://github.com/0dayNinja/CVE-2021-24155.rb

This is a functional Metasploit module that exploits an arbitrary file upload vulnerability in the WordPress Backup Guard plugin (versions < 1.6.0) to achieve authenticated remote code execution. The exploit uploads a malicious PHP file and triggers it via a crafted HTTP request.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WordPress Backup Guard plugin < 1.6.0
Auth required
Prerequisites: Valid WordPress admin credentials · Backup Guard plugin < 1.6.0 installed
devstral-2 · analyzed Feb 18, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Nguyen Van Khanh, Ron Jost · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/wp_plugin_backup_guard_rce.rb

This Metasploit module exploits an arbitrary file upload vulnerability in WordPress Backup Guard plugin versions < 1.6.0, allowing authenticated users to upload a malicious PHP file and execute it, resulting in remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WordPress Backup Guard plugin < 1.6.0
Auth required
Prerequisites: Valid WordPress admin credentials · Backup Guard plugin < 1.6.0 installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

WordPress BackupGuard <1.6.0 - Authenticated Arbitrary File Upload
HIGHVERIFIEDby theamanrawat

References (3)

Core 3
Core References
Exploit, Third Party Advisory x_refsource_confirm
https://wpscan.com/vulnerability/d442acac-4394-45e4-b6bb-adf4a40960fb
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/163382/WordPress-Backup-Guard-1.5.8-Shell-Upload.html

Scores

CVSS v3 7.2
EPSS 0.8369
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
backup-guard/backup_guard < 1.6.0
Published Apr 05, 2021
Tracked Since Feb 18, 2026