Vulnerabilities > CVE-2023-4637 - Missing Authorization vulnerability in Wpvivid Migration, Backup, Staging

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
wpvivid
CWE-862

Summary

The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the restore() and get_restore_progress() function in versions up to, and including, 0.9.94. This makes it possible for unauthenticated attackers to invoke these functions and obtain full file paths if they have access to a back-up ID.

Vulnerable Configurations

Part Description Count
Application
Wpvivid
93

Common Weakness Enumeration (CWE)