
Python proof-of-concept exploit for CVE-2023-6553, demonstrating unauthenticated remote code execution via PHP filter chain in the Backup Migration WordPress plugin.
Unauthenticated Remote Code Execution in Backup Migration (WordPress Plugin).
$ python exploit.py
The following PHP script is executed.
<?php `date > out.txt`; ?>