Impact
The WPvivid Backup for MainWP plugin contains a stored cross‑site scripting flaw in its admin settings. An attacker who can log into the site as an administrator can inject arbitrary JavaScript that is persisted and executed whenever a user visits the affected page. The injected code can hijack sessions, steal credentials, or carry out other malicious actions in the context of the victim’s browser. The weakness is classified as a failure of input validation and output escaping (CWE‑79).
Affected Systems
This vulnerability affects all installations of WPvivid Backup for MainWP version 0.9.33 and earlier, with the constraint that it only manifests in multi‑site WordPress setups where the unfiltered_html capability is disabled for non‑administrator roles. Users running any of these affected plugin versions in such an environment are exposed to the XSS flaw.
Risk and Exploitability
The CVSS score of 4.4 places the flaw in the low to moderate severity range. Because the exploit requires administrator‑level authentication and involves a stored payload that only affects users who view the modified admin page, the likelihood of widespread impact is limited. The EPSS score of < 1 % and the absence of a KEV listing further suggest a low probability of active exploitation. The primary attack vector is authenticated access to the plugin’s settings via an administrator account.
OpenCVE Enrichment