PT-2012-1866 · WordPress · Backwpup

Phil Taylor

·

Published

2012-10-08

·

Updated

2024-02-14

·

CVE-2011-4342

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions BackWPup plugin versions prior to 1.7.2
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the wpabs parameter in the wp xml export.php file.
Recommendations For versions prior to 1.7.2, update to version 1.7.2 or later to resolve the issue.

Exploit

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2011-4342

Affected Products

Backwpup