Monday, April 28, 2025
HomeCyber Security NewsWordPress Plugin Flaw Exposes 90K+ Websites to Hack Attack

WordPress Plugin Flaw Exposes 90K+ Websites to Hack Attack

Published on

SIEM as a Service

Follow Us on Google News

Over 90,000 websites are currently at risk due to a vulnerability found in the WordPress Backup Migration Plugin. This vulnerability has enabled unauthenticated remote code execution, making it possible for potential attackers to gain access to these websites.

A group of researchers from Nex Team discovered the vulnerability while participating in the Wordfence Bug Bounty program.

It’s worth noting that the CVE-2023-6553 vulnerability, which allows for remote code execution, has been assigned a critical severity score of 9.8.

- Advertisement - Google News

This vulnerability allows arbitrary PHP code to be injected and executed by unauthenticated threat actors on WordPress sites that use this plugin.

Wordpress plugin flaw
WordPress plugin flaw

The Backup Migration plugin for WordPress has a vulnerability in all versions up to and including 1.3.7, which allows attackers to execute remote code.

The vulnerability is present in the /includes/backup-heart.php file, making it possible for attackers to gain unauthorized access to sensitive data and execute malicious code on the website.

Suppose an attacker gains control of a target computer through some vulnerability and gains the power to execute commands on that remote computer. In that case, this process is called Remote Code Execution (RCE).

This indicates that BMI_ROOT_DIR is modifiable by the user. Threat actors can use this vulnerability to insert malicious PHP code into requests and run arbitrary commands on the underlying server under the WordPress instance’s security context.

After the incident, a new version, 1.3.8, was released that included a patch to address the issue.

It is recommended to update the plugin to the latest version as soon as possible to prevent exploitation of this vulnerability.

Latest articles

Cybersecurity Firm CEO Arrested for Planting Malware in Hospital Systems

Jeffrey Bowie, the CEO of a local cybersecurity firm, has been arrested for allegedly...

How To Use Digital Forensics To Strengthen Your Organization’s Cybersecurity Posture

Digital forensics has become a cornerstone of modern cybersecurity strategies, moving beyond its traditional...

Building A Strong Compliance Framework: A CISO’s Guide To Meeting Regulatory Requirements

In the current digital landscape, Chief Information Security Officers (CISOs) are under mounting pressure...

Two Systemic Jailbreaks Uncovered, Exposing Widespread Vulnerabilities in Generative AI Models

Two significant security vulnerabilities in generative AI systems have been discovered, allowing attackers to...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Cybersecurity Firm CEO Arrested for Planting Malware in Hospital Systems

Jeffrey Bowie, the CEO of a local cybersecurity firm, has been arrested for allegedly...

How To Use Digital Forensics To Strengthen Your Organization’s Cybersecurity Posture

Digital forensics has become a cornerstone of modern cybersecurity strategies, moving beyond its traditional...

Building A Strong Compliance Framework: A CISO’s Guide To Meeting Regulatory Requirements

In the current digital landscape, Chief Information Security Officers (CISOs) are under mounting pressure...