PT-2024-10038 · WordPress · Super Backup & Clone - Migrate

Tonn

·

Published

2024-09-27

·

Updated

2024-12-24

·

CVE-2024-9290

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Super Backup & Clone - Migrate plugin for WordPress versions prior to 2.3.4
Description The issue is related to arbitrary file uploads due to missing file type validation and a missing capability check on the ibk restore migrate check() function. This allows unauthenticated attackers to upload arbitrary files on the affected site's server, which may make remote code execution possible.
Recommendations For versions prior to 2.3.4, update to version 2.3.4 to fix this issue. As a temporary workaround, consider disabling the ibk restore migrate check() function until a patch is available. Restrict access to the plugin's file upload functionality to minimize the risk of exploitation.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BDU:2025-00174
CVE-2024-9290

Affected Products

Super Backup & Clone - Migrate