CVE · Critical

CVE-2023-5576 — WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.92

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-5576 WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.92 Exposure of Sensitive Information to an Unauthorized Actor Critical 9.3 < 0.9.92 0.9.92 2023-10-13

CVE-2023-5576

The WPvivid Backup, Migration & Staging plugin through version 0.9.91 stores Google Drive API credentials in plaintext within publicly accessible plugin files, exposing sensitive authentication data. An unauthenticated attacker could potentially gain access to the WPvivid Google Drive account by exploiting these exposed secrets in combination with social engineering or other vulnerabilities that trigger user reauthentication. This vulnerability was patched in version 0.9.92.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.