Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-59168 | The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 via the 'content-backups' and 'content-name', 'content-manifest', or 'content-bmitmp' and 'content-identy' HTTP headers. This makes it possible for unauthenticated attackers to delete arbitrary files, including the wp-config.php file, which can make site takeover and remote code execution possible. |
Wed, 08 Apr 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Backup Migration <= 1.3.9 - Unauthenticated Path Traversal to Arbitrary File Deletion | |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:34:37.988Z
Reserved: 2023-12-20T01:43:10.286Z
Link: CVE-2023-6972
No data.
Status : Modified
Published: 2023-12-23T02:15:45.333
Modified: 2026-04-08T17:17:18.290
Link: CVE-2023-6972
No data.
OpenCVE Enrichment
No data.
EUVD