PT-2024-10845 · WordPress · Wpvivid

·

CVE-2020-36835

·

Published

2024-10-15

·

Updated

2025-02-27

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Migration, Backup, Staging – WPvivid plugin for WordPress versions up to, and including 0.9.35
Description The issue concerns sensitive information disclosure of a WordPress site's database due to missing capability checks on the wp ajax wpvivid add remote AJAX action. This allows low-level authenticated attackers to send backups to a remote location of their choice for review.
Recommendations For versions up to, and including 0.9.35, update to the latest version immediately to secure the site. As a temporary workaround, consider restricting access to the wp ajax wpvivid add remote AJAX action until the update is applied.

Fix

Missing Authorization

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-36835

Affected Products

Wpvivid