CVE · High

CVE-2024-3054 — WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.100

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-3054 WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.100 Deserialization of Untrusted Data High 7.2 < 0.9.100 0.9.100 2024-04-11

CVE-2024-3054

The WPvivid Backup & Migration plugin for WordPress has a PHAR deserialization vulnerability affecting versions up to 0.9.99 where the wpvividstg_get_custom_exclude_path_free action fails to properly validate the tree_node[node][id] parameter, allowing authenticated administrators to instantiate arbitrary PHP objects through PHAR wrappers. While the plugin itself lacks a gadget chain for code execution, the presence of one in other installed plugins or themes could enable attackers to delete files, access sensitive information, or execute arbitrary code.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.