PT-2024-10845 · WordPress · Wpvivid
Webarx Security
·
Published
2024-10-15
·
Updated
2025-02-27
·
CVE-2020-36835
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Migration, Backup, Staging – WPvivid plugin for WordPress versions up to, and including 0.9.35
Description
The issue concerns sensitive information disclosure of a WordPress site's database due to missing capability checks on the
wp ajax wpvivid add remote AJAX action. This allows low-level authenticated attackers to send backups to a remote location of their choice for review.Recommendations
For versions up to, and including 0.9.35, update to the latest version immediately to secure the site. As a temporary workaround, consider restricting access to the
wp ajax wpvivid add remote AJAX action until the update is applied.Fix
Missing Authorization
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wpvivid