CVE · High

CVE-2022-2442 — WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.76

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-2442 WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.76 Deserialization of Untrusted Data High 7.2 < 0.9.76 0.9.76 2022-08-10

CVE-2022-2442

The WPvivid backup and migration plugin contains a deserialization vulnerability affecting versions through 0.9.74 in the 'path' parameter that allows administrators to exploit PHAR wrappers to instantiate arbitrary PHP objects, potentially enabling malicious code execution if a suitable object chain exists and the attacker successfully uploads a file containing the serialized payload. Only authenticated users with administrative access can exploit this flaw. The vulnerability was patched in version 0.9.76.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.