A path traversal vulnerability exists in the Backup Migration plugin for WordPress in all versions up to and including 1.3.9. The vulnerability is triggered via manipulation of the 'content-backups', 'content-name', 'content-manifest', 'content-bmitmp', and 'content-identy' HTTP headers, allowing unauthenticated attackers to delete arbitrary files on the server, including critical files such as wp-config.php.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python PoC for CVE-2023-6972 affecting the WordPress Backup Migration plugin (backup-backup) <= 1.3.9. Repository structure is minimal: README.md documents the vulnerability and usage, requirements.txt lists requests and rich, and exploit.py contains all exploit logic and CLI handling. The exploit has two modes. In check mode, it performs a GET request to /wp-content/plugins/backup-backup/readme.txt on a supplied target URL, parses the 'Stable tag' line, and reports the target as vulnerable if the version string is <= 1.3.9. In exploit mode, it sends a POST request to /wp-content/plugins/backup-backup/includes/backup-heart.php with a set of crafted HTTP headers intended to abuse the vulnerable plugin's path handling and delete an attacker-specified file. The attacker supplies the target base URL, a directory path, and a filename; the script then constructs a relative payload path of the form ./<last_directory>/<file_name> and places it into the Content-Identy header while also setting Content-Bmitmp, Content-Backups, and Content-Name. Main capability: unauthenticated arbitrary file deletion on vulnerable WordPress installations. The README notes this can be chained toward RCE by deleting wp-config.php, but the provided code itself does not implement code execution, shell delivery, persistence, or post-exploitation. It is therefore a real exploit PoC with a basic hardcoded payload structure rather than a detection-only script. Notable implementation details: the script disables TLS verification warnings and performs requests with verify=False, uses argparse subcommands for check/exploit, and uses rich for formatted console output. Hardcoded filesystem assumptions include /var/www/html/ and /var/www/html/wp-content/plugins/backup-backup/, which may limit reliability across nonstandard WordPress deployments.
Small standalone Python exploit repository for CVE-2023-6972 targeting the WordPress Backup Migration plugin (backup-backup) <= 1.3.9. The repository contains three files: a README with usage and vulnerability context, a requirements file listing requests and rich, and a single executable script exploit.py. The script implements two modes: check and exploit. In check mode, it performs an unauthenticated GET request to /wp-content/plugins/backup-backup/readme.txt, parses the 'Stable tag' value, and compares it to 1.3.9 to assess likely vulnerability. In exploit mode, it sends a POST request to /wp-content/plugins/backup-backup/includes/backup-heart.php with crafted custom headers that encode filesystem paths and a target filename, aiming to trigger arbitrary file deletion. The payload is not a shell or code execution payload; it is an HTTP header-based file deletion primitive. The script includes a polished CLI with rich-formatted output, disables TLS verification warnings, and uses hardcoded Linux/WordPress path assumptions such as /var/www/html/. Overall, this is a real, operational PoC exploit for unauthenticated arbitrary file deletion against a specific vulnerable WordPress plugin, with detection capability built in and exploitation requiring operator-supplied target path and filename.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.