The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the get_restore_progress() and restore() functions in all versions up to, and including, 0.9.68. This makes it possible for unauthenticated attackers to exploit a SQL injection vulnerability or trigger a DoS.
References
Configurations
History
No history.
Information
Published : 2024-02-29 07:15
Updated : 2025-01-16 18:57
NVD link : CVE-2024-1982
Mitre link : CVE-2024-1982
CVE.ORG link : CVE-2024-1982
JSON object : View
Products Affected
wpvivid
- migration\,_backup\,_staging
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
