CVE · High

CVE-2023-41243 — WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.91

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-41243 WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.91 Improper Privilege Management High 8.8 < 0.9.91 0.9.91 2023-09-12

CVE-2023-41243

The WPvivid Backup Plugin for WordPress contains a capability check vulnerability in versions up to 0.9.90 affecting the 'start_staging' and 'get_staging_progress' functions, allowing authenticated attackers to bypass authorization controls. Exploiting this flaw enables attackers to set up staging environments and new WordPress installations using arbitrary database connections of their choosing. By controlling the database, an attacker can grant themselves administrator access and leverage the shared file system between the new and victim sites to achieve complete site compromise.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.