CVE-2024-3054
The WPvivid Backup & Migration plugin for WordPress has a PHAR deserialization vulnerability affecting versions up to 0.9.99 where the wpvividstg_get_custom_exclude_path_free action fails to properly validate the tree_node[node][id] parameter, allowing authenticated administrators to instantiate arbitrary PHP objects through PHAR wrappers. While the plugin itself lacks a gadget chain for code execution, the presence of one in other installed plugins or themes could enable attackers to delete files, access sensitive information, or execute arbitrary code.
Based on public CVE data (MITRE/NVD).