ZeroDay Vulnerability Found in BackupBuddy WordPress Plugin

backupbuddy wordpress plugin

On September 6th, 2022, iThemes, the creator of the BackupBuddy WordPress plugin, announced a security vulnerability found to be exploited since August 27th, 2022. This vulnerability only impacts sites running BackupBuddy versions 8.5.8.0 through 8.7.4.1.

There are indications that this vulnerability is still being actively exploited. However, ithemes readily patched the vulnerability and has requested its users to ensure they are using the 8.7.5 or higher version of the BackBuddy plugin.

What Should I Do?

Update immediately to the latest 8.7.5 patched version.

The breach allowed malicious users to view the contents of any file on a server that a WordPress installation can read.

Examples are the WordPress wp-config.php file and, depending on the server setup, other sensitive files like /etc/passwd. Therefore, it is imperative to upgrade immediately to the latest safe version.

How to Tell if I Am Affected

You can diagnose if your site has been compromised by finding any text containing local-destination-id and wp-config.php with an HTTP 2xx Response in your server logs.

The security breach was identified on BackBuddy versions 8.5.8.0 to 8.7.4.1.

Additional Information

If you need additional information or help directly from ithemes, please open a ticket through the iThemes Help Desk.

Start Creating Web Apps on Managed Cloud Servers Now

Easy Web App Deployment for Agencies, Developers and E-Commerce Industry.

Zero-Day Vulnerability Found in BackupBuddy WordPress Plugin 1

Marianna Siouti

Marianna Siouti is a Product Marketing Manager at Cloudways. She has over 14 years of experience in the hosting industry, in Marketing and Product. She is someone who falls in love with problems and works towards solving them with technology. You will find her working remotely from warm places, or on LinkedIn.

×

Get Our Newsletter
Be the first to get the latest updates and tutorials.

Thankyou for Subscribing Us!

Do you like what you read?

Thank you for your feedback!

Keep reading the article at The Official Cloudways Blog. The article was originally written by Marianna Siouti on 2022-09-19 11:56:49.

The article was hand-picked and curated for you by the Editorial Team of WP Archives.

Disclosure: Some of the links in this post are "affiliate links." This means if you click on the link and purchase the product, We may receive an affiliate commission.

Leave a Comment

Your email address will not be published. Required fields are marked *

Show Your ❤️ Love! Like Us
Scroll to Top