CVE-2024-10962
The WPvivid backup and migration plugin through version 0.9.107 contains a PHP object injection vulnerability in the 'replace_row_data' and 'replace_serialize_data' functions that process unserialized data without proper validation. Unauthenticated attackers can exploit this flaw to inject malicious PHP objects, though the plugin itself lacks a known gadget chain for direct exploitation. If complementary plugins or themes on the site contain exploitable gadget chains, an attacker could potentially execute arbitrary code, steal sensitive information, or delete files, with the caveat that an administrator must initiate the creation of a staging site to trigger the vulnerability.
Based on public CVE data (MITRE/NVD).