We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-7315

Migration, Backup, Staging – WPvivid < 0.9.106 - Unauthenticated Sensitive Data Exposure



AssignerWPScan
Reserved2024-07-30
Published2024-10-02
Updated2024-10-02

Description

The Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient randomness in the filename that is created when generating a backup, which could be bruteforced by attackers to leak sensitive information about said backups.

Problem types

CWE-200 Information Exposure

Product status

Default status
unaffected

0.9.103 before 0.9.106
affected

Credits

Dmitrii Ignatyev 0x4006716660

WPScan 0x4006716670

References

https://wpscan.com/vulnerability/456b728b-a451-4afb-895f-850ddc4fb589/ exploit vdb-entry technical-description

cve.org CVE-2024-7315

nvd.nist.gov CVE-2024-7315

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.