CVSS v3
7.2
HIGH
EPSS Score
93.1%
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported files are of the SGBP format and extension, allowing high privilege users (admin+) to upload arbitrary files, including PHP ones, leading to RCE.
The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported files are of the SGBP format and extension, allowing high privilege users (admin+) to upload arbitrary files, including PHP ones, leading to RCE.
Active exploitation of CVE-2021-24155 has not been confirmed. The EPSS score is 93.1%, indicating the estimated probability of exploitation in the next 30 days.
CVE-2021-24155 has a CVSS v3 base score of 7.2 (HIGH severity).
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
Ranked by exploit probability (EPSS).