CVE-2023-41243
The WPvivid Backup Plugin for WordPress contains a capability check vulnerability in versions up to 0.9.90 affecting the 'start_staging' and 'get_staging_progress' functions, allowing authenticated attackers to bypass authorization controls. Exploiting this flaw enables attackers to set up staging environments and new WordPress installations using arbitrary database connections of their choosing. By controlling the database, an attacker can grant themselves administrator access and leverage the shared file system between the new and victim sites to achieve complete site compromise.
Based on public CVE data (MITRE/NVD).