Impact
The BackWPup WordPress plugin before version 5.7.7 fails to constrain the destination path used when extracting files during a backup restore that relies on its fallback archive library. This flaw permits administrators to write files outside the intended restore directory, effectively allowing them to place arbitrary code on the server and execute it. The vulnerability is a direct path‑traversal weakness that can lead to full remote code execution if attacker‑controlled files are injected into the plugin’s working area.
Affected Systems
The plugin BackWPup versions earlier than 5.7.7 are affected. The issue exists across all platforms where the plugin is installed and the fallback restore mechanism is utilized; no vendor name is listed in the CNA data, so all installations of the unpatched BackWPup plugin are potentially vulnerable.
Risk and Exploitability
No EPSS or KEV data are available for this vulnerability. The CVSS score is not specified, but the described impact of unrestricted file writes and the ability to execute arbitrary code imply a high severity. The likely attack vector is a local privileged administrator who can trigger the backup restoration process. Without patching, malicious actors can craft a restore job that places exploit files into critical directories. The absence of a public exploit or KEV listing does not diminish the risk to affected sites because the attack requires administrative access, which is often present on compromised or poorly secured WordPress installations.
OpenCVE Enrichment