WordPress Plugin Vulnerabilities

Migration, Backup, Staging – WPvivid < 0.9.106 - Unauthenticated Sensitive Data Exposure

Description

The plugin does not use sufficient randomness in the filename that is created when generating a backup, which could be bruteforced by attackers to leak sensitive information about said backups.

Proof of Concept

Affects Plugins

Fixed in 0.9.106

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE
CVSS

Miscellaneous

Original Researcher
Dmitrii Ignatyev
Submitter
Dmitrii Ignatyev
Verified
Yes

Timeline

Publicly Published
2024-09-11 (about 1 year ago)
Added
2024-09-11 (about 1 year ago)
Last Updated
2024-09-11 (about 1 year ago)

Other