The Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient randomness in the filename that is created when generating a backup, which could be bruteforced by attackers to leak sensitive information about said backups.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-48256 The Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient randomness in the filename that is created when generating a backup, which could be bruteforced by attackers to leak sensitive information about said backups.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 16 May 2025 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Wpvivid
Wpvivid migration\, Backup\, Staging
Weaknesses CWE-338
CPEs cpe:2.3:a:wpvivid:migration\,_backup\,_staging:*:*:*:*:*:wordpress:*:*
Vendors & Products Wpvivid
Wpvivid migration\, Backup\, Staging

Wed, 02 Oct 2024 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Wpvivid Team
Wpvivid Team migration Backup Staging
CPEs cpe:2.3:a:wpvivid_team:migration_backup_staging:*:*:*:*:*:*:*:*
Vendors & Products Wpvivid Team
Wpvivid Team migration Backup Staging
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Oct 2024 06:15:00 +0000

Type Values Removed Values Added
Description The Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient randomness in the filename that is created when generating a backup, which could be bruteforced by attackers to leak sensitive information about said backups.
Title Migration, Backup, Staging – WPvivid < 0.9.106 - Unauthenticated Sensitive Data Exposure
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2025-08-27T12:00:47.136Z

Reserved: 2024-07-30T21:02:19.738Z

Link: CVE-2024-7315

cve-icon Vulnrichment

Updated: 2024-10-02T16:33:34.499Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-02T06:15:09.963

Modified: 2025-05-16T20:32:49.070

Link: CVE-2024-7315

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.