WP Clinic
Log in Sign up

CVE · Critical

CVE-2024-3412 — WP STAGING – WordPress Backup, Restore, Migration & Clone [wp-staging] < 3.5.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-3412 WP STAGING – WordPress Backup, Restore, Migration & Clone [wp-staging] < 3.5.0 Unrestricted Upload of File with Dangerous Type Critical 9.1 < 3.5.0 3.5.0 2024-05-28

CVE-2024-3412

The WP STAGING WordPress Backup Plugin – Migration Backup Restore plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wpstg_processing AJAX action in all versions up to, and including, 3.4.3. This makes it possible for authenticated attackers, with administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

Source: CVE.org

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.