Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-36835

Опубликовано: 16 окт. 2024
Источник: nvd
CVSS3: 4.9
CVSS3: 6.5
EPSS Низкий

Описание

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a WordPress site's database due to missing capability checks on the wp_ajax_wpvivid_add_remote AJAX action that allows low-level authenticated attackers to send back-ups to a remote location of their choice for review. This affects versions up to, and including 0.9.35.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wpvivid:migration\,_backup\,_staging:*:*:*:*:*:wordpress:*:*
Версия до 0.9.36 (исключая)

EPSS

Процентиль: 43%
0.00209
Низкий

4.9 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-200
CWE-862

Связанные уязвимости

CVSS3: 4.9
github
больше 1 года назад

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a WordPress site's database due to missing capability checks on the wp_ajax_wpvivid_add_remote AJAX action that allows low-level authenticated attackers to send back-ups to a remote location of their choice for review. This affects versions up to, and including 0.9.35.

EPSS

Процентиль: 43%
0.00209
Низкий

4.9 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-200
CWE-862