MEDIUM
WPvivid Backup < 0.9.76 - Admin+ Arbitrary File Read
Published Sep 16, 2022
4.9
MEDIUMCVSS 3.1
EPSS 25.29%
Description
The Migration, Backup, Staging WordPress plugin before 0.9.76 does not sanitise and validate a parameter before using it to read the content of a file, allowing high privilege users to read any file from the web server via a Traversal attack
Affected products
- Vendor n/a Product Migration, Backup, Staging – WPvivid Defaultn/a
- Version 0.9.76StatusaffectedConstraints<0.9.76
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Migration, Backup, Staging – WPvivid | n/a |
|
- < 0.9.76
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- http://packetstormsecurity.com/files/168616/WordPress-WPvivid-Backup-Path-Traversal.html ExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2022/Oct/0 mailing-listExploitMailing ListThird Party Advisory
- https://wpscan.com/vulnerability/cb6a3304-2166-47a0-a011-4dcacaa133e5 ExploitPatchThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/168616/WordPress-WPvivid-Backup-Path-Traversal.html | ExploitThird Party AdvisoryVDB Entry | |
| http://seclists.org/fulldisclosure/2022/Oct/0 | mailing-listExploitMailing ListThird Party Advisory | |
| https://wpscan.com/vulnerability/cb6a3304-2166-47a0-a011-4dcacaa133e5 | ExploitPatchThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Sep 16, 2022
Updated Aug 3, 2024
Reserved Aug 16, 2022
Link CVE-2022-2863
CISA Vulnrichment
Updated n/a