CVE · High

CVE-2020-36842 — WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.36

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-36842 WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.36 Unrestricted Upload of File with Dangerous Type High 8.8 < 0.9.36 0.9.36 2020-03-13

CVE-2020-36842

The WPvivid plugin for WordPress versions up to 0.9.35 contains a vulnerability in its AJAX handlers wpvivid_upload_import_files and wpvivid_upload_files that fail to properly verify user permissions, enabling authenticated users with minimal privileges to upload arbitrary zip files to the server. Once uploaded, these zip files can be extracted, potentially allowing attackers to place malicious files on the affected website. The vulnerability was remedied in version 0.9.36.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.