CVE-2023-6972
CRITICALBackup Migration < 1.3.9 - Unauthenticated Path Traversal via HTTP Headers
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2023-6972. PoCs published by 0x00phantom-hat, Aliyankhan-source.
AI-analyzed exploit summary This repository contains a functional Python exploit for CVE-2023-6972, an unauthenticated arbitrary file deletion vulnerability in the WordPress Backup Migration plugin (<=1.3.9). The exploit automates both vulnerability checking and exploitation, allowing deletion of arbitrary files via a crafted request to the vulnerable endpoint.
Description
The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 via the 'content-backups' and 'content-name', 'content-manifest', or 'content-bmitmp' and 'content-identy' HTTP headers. This makes it possible for unauthenticated attackers to delete arbitrary files, including the wp-config.php file, which can make site takeover and remote code execution possible.
Exploits (2)
This repository contains a functional Python exploit for CVE-2023-6972, an unauthenticated arbitrary file deletion vulnerability in the WordPress Backup Migration plugin (<=1.3.9). The exploit automates both vulnerability checking and exploitation, allowing deletion of arbitrary files via a crafted request to the vulnerable endpoint.
This repository contains a functional Python exploit for CVE-2023-6972, an unauthenticated arbitrary file deletion vulnerability in the WordPress Backup Migration plugin (versions <= 1.3.9). The exploit automates both vulnerability checking and exploitation, allowing deletion of arbitrary files, which can be chained to achieve RCE by deleting critical files like wp-config.php.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H