{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3abackupblissbackup_migrationwordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:backupbliss:backup_migration:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-7693"},{"cvss":7.2,"id":"CVE-2023-7002"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Backup Migration plugin (2.1.5.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Backup Migration plugin for WordPress, in all versions up to and including 2.1.5.1, contains an OS Command Injection vulnerability (CVE-2026-7693). This issue arises from improper sanitization of the 'file' POST parameter within the 'restoreBackup' AJAX handler. While the plugin employs 'esc_attr()' to sanitize input, this function is designed for HTML-context output and does not effectively strip shell metacharacters.\u003c/p\u003e\n\u003cp\u003eThe application subsequently concatenates this unquoted input directly into a command string executed by the PHP 'exec()' function. This vulnerability serves as an incomplete fix for a previously identified issue (CVE-2023-7002), which had addressed similar patterns in other handlers but failed to secure this specific code path. Attackers possessing the 'do_backups' capability - typically assigned to administrators - can exploit this to run arbitrary OS commands as the web server user, effectively bypassing standard WordPress security hardening measures such as 'DISALLOW_FILE_EDIT' and 'DISALLOW_FILE_MODS'.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full OS-level command execution with the privileges of the web server service account. This bypasses WordPress application-layer security, potentially leading to complete site compromise, data exfiltration, or deployment of further backdoors on the underlying server environment. The impact is elevated by the ability to circumvent configuration-based protections meant to restrict administrative file system access.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Backup Migration plugin to a version patched against CVE-2026-7693 immediately.\u003c/li\u003e\n\u003cli\u003eReview administrative and user accounts for privilege misuse, specifically monitoring for users assigned the 'do_backups' capability who should not require it.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect POST requests containing suspicious shell metacharacters directed at the 'restoreBackup' AJAX handler.\u003c/li\u003e\n\u003cli\u003eAudit web server access logs for anomalous POST requests to the admin-ajax.php endpoint that contain shell control characters such as semicolons, pipes, or backticks in the 'file' parameter.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-05T09:18:26Z","date_published":"2026-08-05T09:18:26Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-7693-backup-migration-rce/","summary":"The Backup Migration WordPress plugin is vulnerable to authenticated OS command injection in versions up to 2.1.5.1, allowing attackers with administrative capabilities to execute arbitrary shell commands via the restoreBackup AJAX handler.","title":"OS Command Injection in Backup Migration WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-7693-backup-migration-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:backupbliss:backup_migration:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}