"value":"The Total Upkeep \u2013 WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.10 via the compression_level setting. This is due to the plugin using the compression_level setting in proc_open() without any validation. This makes it possible for authenticated attackers, with administrator-level access and above, to execute code on the server."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
"cweId":"CWE-78"
}
]
}
]
},
"affects":{
"vendor":{
"vendor_data":[
{
"vendor_name":"boldgrid",
"product":{
"product_data":[
{
"product_name":"Total Upkeep \u2013 WordPress Backup Plugin plus Restore & Migrate by BoldGrid",