Description
WordPress Plugin Migration, Backup, Staging-WPvivid is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently add a new remote storage location and set it as the default backup location. WordPress Plugin Migration, Backup, Staging-WPvivid version 0.9.35 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 0.9.36 or latest
References
Related Vulnerabilities
WebLogic Deserialization of Untrusted Data Vulnerability (CVE-2019-16335)
Apache HTTP Server Improper Input Validation Vulnerability (CVE-2017-15715)
WordPress Plugin Front-End Only Users Cross-Site Scripting (3.1.10)
WordPress Plugin gboutique Local File Inclusion (1.3)
WordPress Improper Input Validation Vulnerability (CVE-2007-1277)