The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a WordPress site's database due to missing capability checks on the wp_ajax_wpvivid_add_remote AJAX action that allows low-level authenticated attackers to send back-ups to a remote location of their choice for review. This affects versions up to, and including 0.9.35.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Oct 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 16 Oct 2024 07:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a WordPress site's database due to missing capability checks on the wp_ajax_wpvivid_add_remote AJAX action that allows low-level authenticated attackers to send back-ups to a remote location of their choice for review. This affects versions up to, and including 0.9.35. | |
Title | Migration, Backup, Staging – WPvivid <= 0.9.35 - Sensitive Information Disclosure | |
Weaknesses | CWE-200 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-16T06:43:36.927Z
Updated: 2024-10-16T15:32:03.453Z
Reserved: 2024-10-15T18:34:53.551Z
Link: CVE-2020-36835
Vulnrichment
Updated: 2024-10-16T15:31:59.058Z
NVD
Status : Awaiting Analysis
Published: 2024-10-16T07:15:08.387
Modified: 2024-10-16T16:38:14.557
Link: CVE-2020-36835
Redhat
No data.