Description
WordPress Plugin Migration, Backup, Staging-WPvivid is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently add a new remote storage location and set it as the default backup location. WordPress Plugin Migration, Backup, Staging-WPvivid version 0.9.35 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 0.9.36 or latest
References
Related Vulnerabilities
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-3092)
OpenVPN AS Improper Authentication Vulnerability (CVE-2020-15077)
Liferay DXP Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2024-26265)
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-7838)