CVE-2023-6553Disclosure(backupbliss / backup_migration)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Prioritize remediation for backupbliss backup_migration systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the values passed to an include, and subsequently leverage that to achieve remote code execution. This makes it possible for unauthenticated attackers to easily execute code on the server.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • backup_migration

Threat summary

  • Public PoC and exploit tooling are both present
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-08-07)
  • 3 total mentions across 2 days

Affected systems

Products
backup_migration

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-06: 1Mentions · 2026-08-07: 2PoC Mentioned / Linked · 2026-03-06: 1PoC Mentioned / Linked · 2026-08-07: 1Exploit Tool / Code · 2026-08-07: 1Technical Details · 2026-03-06: 103-0608-07
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-061
Disclosure1
2026-08-072
Disclosure1PoC1
Full discourse3 posts
  • ExploitGrid@exploitgrid
    Disclosure

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: EGE-GH-6VzYuGW ( CVE-2025-32432 ) EGE-GH-xiVZBJy ( CVE-2026-0092 ) EGE-GH-eHNcyov ( CVE-2024-21413 ) EGE-GH-9UtrTVp ( CVE-2024-21413 ) EGE-GH-Ix6VGxH ( CVE-2023-6553 ) ..🧵👇

    Post summary

    The tweet is a daily ExploitGrid digest announcing the disclosure of multiple CVEs, with no additional technical, exploit, or mitigation details provided.

    20011173
    365 followersView on X
  • Red Secure Tech Ltd.@redsecuretech
    Disclosure

    CVE-2023-6553: Unauthenticated remote code execution in Backup Migration ≤1.3.7 via PHP filter chain in backup-heart.php. https://www.redsecuretech.co.uk/blog/post/unauth-rce-in-wordpress-backup-plugin/1002 #CyberSecurity #WordPress #CVE #RCE #PluginVulnerability #WordPressSecurity #BackupMigration #InfoSec #WebSecurity #Exploit https://t.co/Een9aJHGE5

    Post summary

    The tweet discloses CVE‑2023‑6553, a remote code execution flaw in Backup Migration plugin, and references a blog link that likely contains a PoC.

    0101063
    40 followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [EXPLOIT] EGE-GH-Ix6VGxH [CRITICAL/PoC] Linked: CVE-2023-6553 CVE-2023-6553 🔗 https://exploitgrid.net/exploits/831c01aa-5303-4d35-bf74-7802ccee0008

    Post summary

    A Proof‑of‑Concept and exploit code for CVE‑2023‑6553 are announced and linked via ExploitGrid, but no active exploitation or patch information is disclosed.

    1000045
    29 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbackupblissbackup_migration-wordpress-

Explore more