Wordpress Alert: Command injection in backup tools
A backup option is passed unsafely to a system command. The server may execute unintended commands.
What it looks like
A backup option is passed unsafely to a system command.
Why it matters
The server may execute unintended commands.
What to check
Review backup tooling for command construction from user-controlled input.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See OWASP injection prevention.
- Categories: WordPress
- Tags: #WordPress Security, #Injection