CVE-2024-1982

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the get_restore_progress() and restore() functions in all versions up to, and including, 0.9.68. This makes it possible for unauthenticated attackers to exploit a SQL injection vulnerability or trigger a DoS.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wpvivid:migration\,_backup\,_staging:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2024-02-29 07:15

Updated : 2025-01-16 18:57


NVD link : CVE-2024-1982

Mitre link : CVE-2024-1982

CVE.ORG link : CVE-2024-1982


JSON object : View

Products Affected

wpvivid

  • migration\,_backup\,_staging
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')