Migration, Backup, Staging – WPvivid <= 0.9.75 - Authenticated (Admin+) Directory Traversal

2022-08-16 00:00
Anonymous

Strategic Overview

Status
Patched in 0.9.76
Affected Version<= 0.9.75
CVSS6.0Medium
CVEN/A
View all WPvivid — Backup, Migration & Staging vulnerabilities

Vulnerability Overview

The WPvivid plugin for WordPress is vulnerable to directory traversal in versions up to, and including, 0.9.75. This allows authenticated users with administrative privileges to download arbitrary files on the server, including sensitive configuration files, though the file size must be successfully guessed in order to do so.

Technical Analysis

REMEDIATION: Update to version 0.9.76, or a newer patched version --- IDENTIFIER: CWE-23 (Relative Path Traversal) The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as .. that can resolve to a location that is outside of that directory.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C