The Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient randomness in the filename that is created when generating a backup, which could be bruteforced by attackers to leak sensitive information about said backups.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Oct 2024 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wpvivid Team
Wpvivid Team migration Backup Staging |
|
CPEs | cpe:2.3:a:wpvivid_team:migration_backup_staging:*:*:*:*:*:*:*:* | |
Vendors & Products |
Wpvivid Team
Wpvivid Team migration Backup Staging |
|
Metrics |
cvssV3_1
|
Wed, 02 Oct 2024 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient randomness in the filename that is created when generating a backup, which could be bruteforced by attackers to leak sensitive information about said backups. | |
Title | Migration, Backup, Staging – WPvivid < 0.9.106 - Unauthenticated Sensitive Data Exposure | |
References |
|
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2024-10-02T06:00:02.453Z
Updated: 2024-10-02T16:33:45.248Z
Reserved: 2024-07-30T21:02:19.738Z
Link: CVE-2024-7315
Vulnrichment
Updated: 2024-10-02T16:33:34.499Z
NVD
Status : Awaiting Analysis
Published: 2024-10-02T06:15:09.963
Modified: 2024-10-04T13:50:43.727
Link: CVE-2024-7315
Redhat
No data.