Extension WordPress
Vulnérabilités WPvivid , Backup, Migration & Staging, page 2
Cette page rassemble les failles publiées pour WPvivid , Backup, Migration & Staging, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WPvivid , Backup, Migration & Staging
27 fiches
Migration, Backup, Staging – WPvivid <= 0.9.74 – Authenticated (Admin+) PHAR Deserialization
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to deserialization of untrusted input via the 'path' parameter in versions up to, and including 0.9.74. This makes it possible for authenticated attackers with administrative privileges to…
*-0.9.74
0.9.75
10/08/2022
Migration, Backup, Staging – WPvivid <= 0.9.70 – Authenticated Arbitrary File Read
Arbitrary File Read vulnerability in WPvivid Team Migration, Backup, Staging – WPvivid (WordPress plugin) versions
*-0.9.70
0.9.71
07/04/2022
Migration, Backup, Staging – WPvivid <= 0.9.69 – Reflected Cross-Site Scripting via sub_page Parameter
The Migration, Backup, Staging WordPress plugin before 0.9.70 does not sanitise and escape the sub_page parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
[*, 0.9.70)
0.9.70
21/03/2022
Migration, Backup, Staging – WPvivid <= 0.9.68 – Unauthenticated Stored Cross-Site Scripting
The Migration, Backup, Staging – WPvivid plugin before 0.9.69 does not have authorisation when adding remote storages, and does not sanitise as well as escape a parameter from such unauthenticated requests before outputting it in admin page, leading…
[*, 0.9.69)
0.9.69
31/01/2022
Migration, Backup, Staging – WPvivid <= 0.9.55 – Reflected Cross-Site Scripting
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 0.9.55 due to insufficient input sanitization and output escaping. This makes it possible…
*-0.9.55
0.9.56
09/08/2021
Migration, Backup, Staging – WPvivid <= 0.9.35 – Sensitive Information Disclosure
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a WordPress site's database due to missing capability checks on the wp_ajax_wpvivid_add_remote AJAX action that allows low-level authenticated attackers to send back-ups…
[*, 0.9.36)
0.9.36
23/03/2020
Migration, Backup, Staging – WPvivid <= 0.9.35 – Authenticated (Subscriber+) Arbitrary File Upload
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the wpvivid_upload_import_files and wpvivid_upload_files AJAX actions that allows low-level authenticated attackers to upload zip files that…
*-0.9.35
0.9.36
13/03/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.