← Back to search

CVE-2026-7693

7.2 HIGH

Published 2026-08-05 · Updated 2026-08-05

AI risk analysis

Summary
The flaw allows authenticated attackers with Administrator-level access to execute arbitrary OS commands as the web-server user through insufficient sanitization of the `file` POST parameter in the Backup Migration plugin for WordPress.
Exploitability
Exploitation requires an attacker to have Administrator-level access or be granted the `do_backups` capability. The vulnerability is relatively straightforward given the lack of proper input validation and command execution safeguards.
Blast radius
If exploited, this could lead to complete compromise of the web server hosting the WordPress site, potentially affecting other sites hosted on the same server due to shared resources or misconfigurations.
Prioritized remediation
Update the Backup Migration plugin to the latest version that addresses this vulnerability. Alternatively, disable and remove the plugin if it is no longer needed.
rceauth-bypasswebwordpress

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2.1.5.1 due to insufficient sanitization of the `file` POST parameter on the `restoreBackup()` AJAX handler. The handler applies `esc_attr()` — an HTML-context sanitizer that does not strip shell metacharacters — and concatenates the result, unquoted, into a `php-cli -f … bmi_restore <file> <remote>` command passed to `exec()`. This makes it possible for authenticated attackers, with Administrator-level access (or any user granted the plugin's `do_backups` capability) and above, to execute arbitrary OS commands as the web-server user, bypassing WordPress hardening constants such as `DISALLOW_FILE_EDIT` and `DISALLOW_FILE_MODS` that would otherwise prevent code execution from the admin UI. This is an incomplete fix of CVE-2023-7002, which patched the same pattern only in the `$_POST['url']` path of `handleQuickMigration()`; the equivalent mitigations (`rawurlencode()` + explicit shell-metachar replacement + double-quoting in `exec()`) were never applied to `$backupName`.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-77

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.