CVE-2021-24155
The WordPress Backup and Migrate Plugin β Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported files are of the SGBP format and extension, allowing high privilege users (admin+) to upload arbitrary files, including PHP ones, leading to RCE.
- Affected products
- Wordpress Backup/Migrate Plugin β Backup Guard
- Backup-guard Backup Guard
- < 1.6.0
- Fix
- Available
- CVSS 3.1
- 7.2 HIGH
- EPSS
- 84.1% (100th percentile)
- Weakness
- CWE-434
- NVD status
- Modified
- Published
- 2021-04-05
CVE-2021-24155 at NVD
10 known exploits for CVE-2021-24155
Proof-of-concept code and exploit modules indexed by Sploitus
Exploits
CVE-2021-24155.rb
Exploit for Unrestricted Upload of File with Dangerous Type in Backup-Guard Backup_Guard
WordPress Backup Guard Authenticated Remote Code Execution Exploit
WordPress Backup Guard Authenticated Remote Code Execution
Wordpress Backup Guard 1.5.8 Plugin - Remote Code Execution (Authenticated) Exploit
Wordpress Plugin Backup Guard 1.5.8 - Remote Code Execution (Authenticated)
WordPress Backup Guard 1.5.8 Shell Upload
Wordpress Plugin Backup Guard - Authenticated Remote Code Execution
Backup Guard < 1.6.0 - Authenticated Arbitrary File Upload