Security Advisory

CVE-2020-36842

8.8
HIGH

Vulnerability Description

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the wpvivid_upload_import_files and wpvivid_upload_files AJAX actions that allows low-level authenticated attackers to upload zip files that can be subsequently extracted. This affects versions up to, and including 0.9.35.
Published Date October 16, 2024
Official Source NIST NVD Advisory