Description
WordPress Plugin Migration, Backup, Staging-WPvivid is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently add a new remote storage location and set it as the default backup location. WordPress Plugin Migration, Backup, Staging-WPvivid version 0.9.35 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 0.9.36 or latest
References
Related Vulnerabilities
Plone CMS Improper Restriction of XML External Entity Reference Vulnerability (CVE-2020-28734)
WordPress Plugin TableOn-WordPress Posts Table Filterable Cross-Site Scripting (1.0.0)
WordPress Plugin Nokia Maps & Places Cross-Site Scripting (1.6.6)
WordPress Plugin Akeeba Backup CORE for WordPress Arbitrary File Upload (1.1.3)