CVE · Medium

CVE-2023-4637 — WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.95

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-4637 WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.95 Missing Authorization Medium 5.3 < 0.9.95 0.9.95 2024-01-19

CVE-2023-4637

The WPvivid Backup and Migration plugin versions prior to 0.9.95 contain a broken access control flaw that allows unauthorized users to perform actions restricted to higher privilege levels due to missing authorization, authentication, or nonce verification in certain functions. Researcher Revan Arifio identified and reported this vulnerability, which has been patched in version 0.9.95 and later. Users should update their installations to version 0.9.95 or newer to resolve the issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.