CVE Database /
CVE-2020-36842
CVE · High
CVE-2020-36842 — WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.36
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2020-36842
|
WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.36 |
Unrestricted Upload of File with Dangerous Type |
High
8.8
|
< 0.9.36
|
0.9.36 |
2020-03-13 |
—
|
CVE-2020-36842
The WPvivid plugin for WordPress versions up to 0.9.35 contains a vulnerability in its AJAX handlers wpvivid_upload_import_files and wpvivid_upload_files that fail to properly verify user permissions, enabling authenticated users with minimal privileges to upload arbitrary zip files to the server. Once uploaded, these zip files can be extracted, potentially allowing attackers to place malicious files on the affected website. The vulnerability was remedied in version 0.9.36.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings