Description
There exists a command injection vulnerability in the Wordpress plugin `wp-database-backup` for versions < 5.2.
For the backup functionality, the plugin generates a `mysqldump` command to execute. The user can choose specific tables to exclude from the backup by setting the `wp_db_exclude_table` parameter in a POST request to the `wp-database-backup` page. The names of the excluded tables are included in the `mysqldump` command unsanitized. Arbitrary commands injected through the `wp_db_exclude_table` parameter are executed each time the functionality for creating a new database backup are run.
Authentication is required to successfully exploit this vulnerability.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/multi/http/wp_db_backup_rcemsf undefined(wp_db_backup_rce) > show actions ...actions...msf undefined(wp_db_backup_rce) > set ACTION < action-name >msf undefined(wp_db_backup_rce) > show options ...show and set options...msf undefined(wp_db_backup_rce) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub