Unauthenticated Remote Code Execution Vulnerability in Super Backup & Clone Migrate for WordPress

CVE-2024-9290
9.8CRITICAL

Key Information

Vendor
Azzaroco
Status
Super Backup & Clone - Migrate For WordPress
Vendor
CVE Published:
13 December 2024

Summary

The Super Backup & Clone - Migrate for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and a missing capability check on the ibk_restore_migrate_check() function in all versions up to, and including, 2.3.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

Affected Version(s)

Super Backup & Clone - Migrate for WordPress <= 2.3.3

Refferences

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database

Credit

Tonn
.