Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-49vr-v9q4-q4ph

Опубликовано: 16 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a WordPress site's database due to missing capability checks on the wp_ajax_wpvivid_add_remote AJAX action that allows low-level authenticated attackers to send back-ups to a remote location of their choice for review. This affects versions up to, and including 0.9.35.

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a WordPress site's database due to missing capability checks on the wp_ajax_wpvivid_add_remote AJAX action that allows low-level authenticated attackers to send back-ups to a remote location of their choice for review. This affects versions up to, and including 0.9.35.

EPSS

Процентиль: 43%
0.00209
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-200
CWE-862

Связанные уязвимости

CVSS3: 4.9
nvd
больше 1 года назад

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a WordPress site's database due to missing capability checks on the wp_ajax_wpvivid_add_remote AJAX action that allows low-level authenticated attackers to send back-ups to a remote location of their choice for review. This affects versions up to, and including 0.9.35.

EPSS

Процентиль: 43%
0.00209
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-200
CWE-862