WordPress · Backup Migration · CVE-2023-7002
**Name of the Vulnerable Software and Affected Versions**
Backup Migration plugin for WordPress versions up to, and including, 1.3.9
**Description**
The issue allows authenticated attackers with administrator-level permissions and above to execute arbitrary commands on the host operating system via the `url` parameter. This is an OS Command Injection vulnerability.
**Recommendations**
For versions up to, and including, 1.3.9, update to a version later than 1.3.9 to resolve the issue.
As a temporary workaround, consider restricting access to the `url` parameter in the affected plugin until a patch is available.