Lucene search

K
wpvulndbWpvulndbWPVDB-ID:4F8178AB-962B-418C-9C31-A7A717C3D6F4
HistoryNov 24, 2023 - 12:00 a.m.

WPvivid Backup Plugin < 0.9.91 - Missing Authorization via 'start_staging' and 'get_staging_progress'

2023-11-2400:00:00
wpscan.com
6
wordpress
vulnerability
data access

6.2 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.0%

Description The WPvivid Backup Plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the ‘start_staging’ and ‘get_staging_progress’ functions in versions up to, and including, 0.9.90. This makes it possible for authenticated attackers to create new staging sites and fresh WordPress installations on the server that use arbitrary database connections under the attacker’s control. This can allow full site takeover via an attacker who grants themselves administrator privileges on the new database, at which point the site they control shares a file system with the victim site.

CPENameOperatorVersion
eq0.9.91

6.2 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.0%

Related for WPVDB-ID:4F8178AB-962B-418C-9C31-A7A717C3D6F4