Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| azzaroco | WP SuperBackup | 0 ~ 2.3.3 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | WP SuperBackup <= 2.3.3 - Unauthenticated Arbitrary File Upload | https://github.com/RandomRobbieBF/CVE-2024-56064 | POC Details |
| 2 | The Super Backup & Clone - Migrate for WordPress plugin (indeed-wp-superbackup) is vulnerable to arbitrary file uploads due to missing file type validation and a missing capability check on the ibk_restore_migrate_check() function in all versions up to and including 2.3.3. Unauthenticated attackers can upload arbitrary PHP files on the affected site's server which leads to remote code execution. Files are written to /wp-content/uploads/isnapshots/. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-56064.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-56068 | 7.5 HIGH | WordPress WP SuperBackup plugin <= 2.3.3 - Subscriber+ PHP Object Injection vulnerability |
| CVE-2024-56067 | 7.5 HIGH | WordPress WP SuperBackup plugin <= 2.3.3 - Unauthenticated Backup File Download Vulnerabil |
| CVE-2024-56070 | 7.4 HIGH | WordPress WP SuperBackup plugin <= 2.3.3 - Multiple Subscriber+ Broken Access Control vuln |
No comments yet