The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions
链接: https://github.com/advisories/GHSA-xwcj-w2w2-2g7c
CVSS 评分: 9.8
参考链接:
https://blog.sucuri.net/2019/06/os-command-injection-in-wp-database-backup.html
https://plugins.trac.wordpress.org/changeset/2078035/wp-database-backup
描述:
The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticated attackers to execute arbitrary commands on the host operating system.
The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions
http://example.com/2025/07/25/github_2441284290/