CVE-2023-6553 is a critical remote code execution vulnerability in the Backup Migration plugin for WordPress affecting all versions up to and including 1.3.7. The flaw is present in the plugin's backup-heart.php component, where attacker-controlled input can influence values passed to an include operation. By controlling that include path or related variables, a remote attacker can cause the application to interpret and execute arbitrary PHP code. The vulnerability is exploitable without authentication and has been described as enabling authentication bypass in practice because no valid WordPress or plugin credentials are required to reach the vulnerable code path. Public reporting also indicates exploitation via a crafted request that abuses an HTTP header to control a plugin directory variable used during processing, ultimately leading to arbitrary PHP execution on the server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
8 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository is a reconstructed WordPress plugin source tree for Backup Migration 1.3.7 plus a README explaining CVE-2023-6553. It is not a standalone exploit script repository; instead it contains the vulnerable application code and documentation showing how the bug works. The main vulnerable component is wp-src/includes/backup-heart.php, a directly accessible PHP file that only checks for POST and then trusts numerous attacker-supplied HTTP headers. Critically, it defines BMI_ROOT_DIR from the content-dir header and then defines BMI_INCLUDES as BMI_ROOT_DIR . 'includes', followed by require_once BMI_INCLUDES . '/bypasser.php'. This creates an unauthenticated header-controlled file inclusion primitive that can lead to RCE when the attacker can point content-dir at a location containing malicious PHP. Exploit capability: unauthenticated remote exploitation over HTTP POST, no nonce or privilege checks, zero-click. The vulnerable endpoint also accepts many other Content-* headers that influence paths and runtime behavior (ABSPATH, WP_CONTENT_DIR, config dir, backups dir, URL, limits, manifest, etc.), but the key sink is the require_once of bypasser.php through attacker-controlled BMI_ROOT_DIR/BMI_INCLUDES. The README explicitly identifies this as PHP file inclusion leading to RCE in Backup Migration <= 1.3.7 and notes that even a deactivated plugin remains exploitable if the file is still present on disk. Repository structure: top-level README documents the vulnerability and impact. wp-src/backup-backup.php is the plugin bootstrap declaring version 1.3.7. wp-src/includes contains activation logic, the vulnerable backup-heart.php endpoint, and analyst.php which initializes a bundled telemetry SDK. The analyst/ subtree is a full opt-in/telemetry framework that registers WordPress AJAX hooks and sends plugin/site metadata to https://feedback.sellcodes.com/api/v1 (logger/install, logger/activate, logger/deactivate, logger/opt-in, logger/opt-out, logger/uninstall). The admin/ and includes/banner/ trees are mostly UI assets, CSS, SVGs, and promotional banner code, not directly related to exploitation. Assessment: valid exploit target code, not fake, not merely detection. Since no ready-made exploit script or weaponized payload is included, maturity is best classified as POC based on vulnerable source and explanatory documentation.
Repository is a full WordPress plugin source tree for Backup Migration 1.3.7, accompanied by a README explaining CVE-2023-6553. This is not a standalone exploit script repository; instead, it contains the vulnerable application code itself plus analysis notes. The core issue is in wp-src/includes/backup-heart.php, a directly reachable POST handler that accepts numerous HTTP headers, lowercases them, and uses them to define runtime constants such as ABSPATH, WP_CONTENT_DIR, BMI_CONFIG_DIR, BMI_BACKUPS, and critically BMI_ROOT_DIR. It then derives BMI_INCLUDES as BMI_ROOT_DIR . 'includes' and executes require_once BMI_INCLUDES . '/bypasser.php'. Because BMI_ROOT_DIR comes from the attacker-controlled Content-Dir header and there is no authentication or nonce check, this creates an unauthenticated file inclusion primitive that can lead to arbitrary PHP execution. Main exploit capability: unauthenticated remote exploitation over HTTP by sending a POST request to backup-heart.php with crafted Content-* headers. The exploit path is effectively header injection into filesystem paths, culminating in require_once of includes/bypasser.php from an attacker-chosen base directory. This is consistent with LFI-to-RCE or direct arbitrary include of attacker-controlled local PHP content. The vulnerable handler also trusts other attacker-supplied paths and values, including config, backups, URL, and resource limits. Repository structure: wp-src/backup-backup.php is the plugin bootstrap; wp-src/includes/ contains operational plugin code including activation logic, the vulnerable backup-heart.php, and bundled subcomponents. The wp-src/analyst/ subtree is a telemetry/opt-in SDK that phones home to feedback.sellcodes.com/api/v1 and is unrelated to the CVE but notable from an endpoint perspective. The wp-src/includes/banner/ subtree is a promotional carousel/installer for other plugins. Most remaining files are admin assets and images. Assessment: valid exploit-relevant repository, not fake, not merely detection. However, because it mainly ships the vulnerable target code and explanatory README rather than a ready-made exploit launcher or weaponized payload, maturity is best classified as POC.
This repository is a small standalone Python exploit for CVE-2023-6553 affecting the WordPress Backup Migration plugin. It contains three files: LICENSE, README.md, and a single executable script, exploit.py. The script is the only code file and serves as the full exploit entry point. The exploit targets the plugin endpoint /wp-content/plugins/backup-backup/includes/backup-heart.php. It abuses the Content-Dir HTTP header to deliver a crafted php://filter chain generated by the php_filter_chain library. That chain causes attacker-controlled PHP code to be included and executed without authentication. The script first performs a vulnerability check by writing a one-character temporary file and then requesting it back from the plugin includes directory. If successful, it proceeds to write a PHP webshell one character at a time, copies it to a randomized .php filename under the plugin includes directory, and deletes the temporary file. The dropped webshell is simple but effective: it executes the contents of GET parameter 0 using PHP backticks and wraps output between [S] and [E] markers so the client can parse command results. The exploit supports two main post-exploitation modes: an interactive command shell over HTTP and a reverse-shell trigger mode added by this fork. In reverse-shell mode, the script sends a single command to the deployed webshell that attempts either a bash /dev/tcp callback or an mkfifo+nc callback to an attacker-supplied host and port. After use, the exploit attempts cleanup by unlinking the dropped PHP shell. Additional functionality includes check-only mode and multi-target scanning from a file using a thread pool. Based on the available code and README, this is a real operational exploit rather than a detector: it performs unauthenticated RCE, drops a persistent webshell temporarily, executes arbitrary commands, and can establish a reverse shell if the target environment permits it.
This repository is a Python proof-of-concept exploit for CVE-2023-6553, targeting the WordPress Backup Migration plugin (backup-backup) versions 1.3.7 and earlier. It is not part of a major exploit framework. The repo contains two executable exploit scripts, exploit.py and fancy_exploit.py, which implement the same attack logic with different console presentation, plus php_filter_chain.py, a helper module that builds the php://filter chain used to smuggle PHP code into the vulnerable include flow. Primary capability: unauthenticated remote code execution against a vulnerable WordPress plugin endpoint. The exploit first performs reconnaissance by requesting /wp-content/plugins/backup-backup/readme.txt and parsing the Stable tag to determine whether the installed plugin version is vulnerable. It then generates a PHP filter-chain payload, delivers it to the vulnerable backup-heart.php logic via the Content-Dir header, and finally triggers a dropped PHP webshell named poc.php under /wp-content/plugins/backup-backup/includes/. The operator can supply an arbitrary OS command for execution. Repository structure is small and focused: README.md documents the vulnerability and usage; exploit.py is the main professional-looking exploit; fancy_exploit.py is a cosmetically enhanced variant with the same functionality; php_filter_chain.py contains the filter-chain generator; requirements.txt lists requests, rich, and packaging. Based on the available code and README, this is an operational exploit with a basic hardcoded payload path rather than a generalized framework module.
This repository is a compact Python exploit project for CVE-2023-6553, targeting the WordPress Backup Migration plugin (backup-backup) versions <= 1.3.7. It contains two main executable scripts, exploit.py and fancy_exploit.py, plus a helper module php_filter_chain.py and a README. Both exploit scripts implement the same attack logic: first perform reconnaissance by requesting the plugin readme at /wp-content/plugins/backup-backup/readme.txt and parsing the Stable tag to determine whether the installed version is vulnerable; then generate a PHP filter-chain payload using the local helper module; then deliver that payload to the vulnerable plugin path described in the README (/wp-content/plugins/backup-backup/includes/backup-heart.php) via the Content-Dir header; and finally trigger a dropped PHP webshell named poc.php under the plugin includes directory to run an attacker-supplied OS command. The helper module php_filter_chain.py is the core payload-generation component. It builds a php://filter chain over php://temp using a large mapping of base64 characters to iconv conversion sequences. This is consistent with known PHP filter-chain exploitation techniques used to transform attacker-controlled input into executable PHP code without directly uploading a file in the normal sense. Repository structure is straightforward: exploit.py is the primary professional-looking CLI entry point with verbose logging and check-only mode; fancy_exploit.py is a cosmetically enhanced variant with the same capabilities; php_filter_chain.py encapsulates filter-chain generation; requirements.txt lists requests, rich, and packaging. The exploit is not merely a detector: it supports actual exploitation and post-exploitation command execution through a webshell, making it an operational PoC rather than a simple scanner.
This repository contains a single Metasploit module (Ruby file) that exploits an unauthenticated remote code execution (RCE) vulnerability in the WordPress Backup Migration plugin (versions <= 1.3.7). The exploit leverages a PHP filter chain technique to prepend a PHP payload to a string, which is then executed via a require statement in the plugin's code. The attack is performed by sending a specially crafted 'Content-Dir' header to the '/wp-content/plugins/backup-backup/includes/backup-heart.php' endpoint, along with a POST request containing the payload. The module supports multiple payloads, including PHP meterpreter shells and command shells for Unix/Linux/Windows platforms. The exploit is weaponized, as it is part of the Metasploit framework and allows for customizable payloads. The code is well-structured, with clear separation of the check and exploit phases, and includes references to the CVE, PoC, and technical write-ups. The main entry point is the Ruby module file, and the only fingerprintable endpoint is the vulnerable PHP file in the WordPress plugin directory.
This repository is a functional exploit for CVE-2023-6553, a remote code execution vulnerability in the Backup Migration WordPress plugin (versions <=1.3.7). The exploit is implemented in Python (exploit.py) and leverages a PHP filter chain generator (php_filter_chain.py) to craft payloads that are delivered to the vulnerable endpoint '/wp-content/plugins/backup-backup/includes/backup-heart.php'. The exploit attempts to write a PHP webshell to the server, which, if successful, allows the attacker to interact with the server via an interactive shell interface. The exploit supports both single-target and multi-target (file-based) modes, with optional multi-threading for bulk scanning. The requirements.txt lists necessary Python dependencies. The README.md provides detailed usage instructions and describes the exploit's capabilities. The main attack vector is unauthenticated network access to the vulnerable WordPress plugin endpoint, and the exploit does not require prior authentication. The payload is a simple PHP webshell that executes arbitrary commands provided by the attacker.
This repository contains a proof-of-concept (PoC) exploit for CVE-2023-6553, a critical unauthenticated remote code execution vulnerability in the WordPress Backup Migration plugin. The repository consists of two files: a README.md describing the vulnerability and usage, and exploit.py, a Python script that automates the exploitation process. The exploit works by crafting a malicious PHP filter chain payload (using techniques inspired by the synacktiv/php_filter_chain_generator) to achieve LFI-to-RCE. The script sends a specially crafted HTTP POST request to the vulnerable plugin endpoint (/wp-content/plugins/backup-backup/includes/backup-heart.php), with a header containing the payload. The default payload executes the 'date' command on the server and writes the output to out.txt, demonstrating arbitrary code execution. The exploit is unauthenticated and requires only network access to the vulnerable WordPress instance. The code is a PoC and does not include advanced features such as payload customization or post-exploitation modules.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated remote code execution vulnerability in version 1.3.7 of the WordPress Backup Migration plugin.
A vulnerability in the WordPress Backup Migration plugin referenced as an exploit simplification PR.
A vulnerability referenced in the context of domains hosting related content; no technical details are provided in the article body.
A critical unauthenticated remote code execution vulnerability in the WordPress Backup Migration plugin that can allow remote attackers to bypass authentication and execute arbitrary PHP code.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.