WordPress.WP.Database.Backup.Plugin.Remote.Command.Injection

description-logoDescription

This indicates an attack attempt to exploit a Arbitrary File Upload vulnerability in WordPress plugin wp-database-backup.
The vulnerability is due to insufficient sanitizing of user supplied inputs in the application when handling a craft HTTP request. An authenticated remote attacker may be able exploit this to execute arbitrary code within the context of the application.

affected-products-logoAffected Products

WordPress plugin wp-database-backup prior to version 5.2

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Upgrade to latest version from the vendor.
https://wordpress.org/plugins/wp-database-backup/

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2019-08-23 14.676 Default_action:pass:drop
2019-08-13 14.668 Name:WordPress.
WP.
Datatbase.
Backup.
Plugin.
Remote.
Command.
Injection:WordPress.
WP.
Database.
Backup.
Plugin.
Remote.
Command.
Injection
2019-08-02 14.664