The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a WordPress site's database due to missing capability checks on the wp_ajax_wpvivid_add_remote AJAX action that allows low-level authenticated attackers to send back-ups to a remote location of their choice for review. This affects versions up to, and including 0.9.35.
Metrics
Affected Vendors & Products
References
History
Thu, 27 Feb 2025 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wpvivid
Wpvivid migration\, Backup\, Staging |
|
Weaknesses | CWE-862 | |
CPEs | cpe:2.3:a:wpvivid:migration\,_backup\,_staging:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Wpvivid
Wpvivid migration\, Backup\, Staging |
Wed, 16 Oct 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 16 Oct 2024 07:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a WordPress site's database due to missing capability checks on the wp_ajax_wpvivid_add_remote AJAX action that allows low-level authenticated attackers to send back-ups to a remote location of their choice for review. This affects versions up to, and including 0.9.35. | |
Title | Migration, Backup, Staging – WPvivid <= 0.9.35 - Sensitive Information Disclosure | |
Weaknesses | CWE-200 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-10-16T15:32:03.453Z
Reserved: 2024-10-15T18:34:53.551Z
Link: CVE-2020-36835

Updated: 2024-10-16T15:31:59.058Z

Status : Analyzed
Published: 2024-10-16T07:15:08.387
Modified: 2025-02-27T18:47:11.020
Link: CVE-2020-36835

No data.