Wordpress backup vuln published
BackWPup has remote execution hole
A remote execution vulnerability has been discovered in Wordpress backup utility BackWPup.
According to Sydney (Australia) company Sense of Security, which published the advisory along with a proof-of-concept, the vulnerability allows local or remote PHP files to be passed to a component of the utility.
“The input passed to the component wp_xml_export.php via the ‘wpabs’ variable allows the inclusion and execution of local or remote PHP files as long as a ‘_nonce’ value is known. The ‘_nonce’ value relies on a static constant which is not defined in the script meaning that it defaults to the value ‘822728c8d9’”, the advisory states.
Sense of Security says the vulnerability affects at least BackWPup Version 1.6.1 (the platform on which it has been tested), and users should upgrade to Version 1.7.1.
Regcast training : Hyper-V 3.0, VM high availability and disaster recovery
COMMENTS
This is a plugin vulnerability, not core wordpress.
So I think the headline could reflect this.
What a non-story ....
The headline makes out that this is a WordPress problem. It's not, it's a problem affecting a single plugin [One of the many WordPress "backup" plugins] which is installed on a small number of WordPress installs (Going by the stats on wordpress.org).
In other news, the number 73 to Camberwick Green ran 5 minutes late this morning ... yawn
We're adults and we aren't amused by this.
"The input passed to the component wp_xml_export.php via the ‘wpabs’ variable allows the inclusion and execution of local or remote PHP files as long as a ‘_nonce’ value is known. The ‘_nonce’ value relies on a static constant which is not defined in the script meaning that it defaults to the value ‘822728c8d9’."
To my fellow readers: There isn't anything funny here, is there? Because you're a grownup, aren't you? Good.

IT infrastructure monitoring strategies
What you need to know about cloud backup
Agentless Backup is Not a Myth
Top 10 SIEM Implementer’s Checklist
Steps to Take Before Choosing a Business Continuity Partner