What the vulnerability does
01Description
Improper Privilege Management vulnerability in WPvivid Team WPvivid Backup and Migration allows Privilege Escalation.This issue affects WPvivid Backup and Migration: from n/a through 0.9.90.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Improper Privilege Management vulnerability in WPvivid Team WPvivid Backup and Migration allows Privilege Escalation.This issue affects WPvivid Backup and Migration: from n/a through 0.9.90.
Explanation of Vulnerability in Simple Terms
WPvivid Backup and Migration versions up to 0.9.90 contain a privilege management flaw that allows authenticated users with low-level access to perform actions restricted to administrators. An attacker with a standard user account can read, modify, or delete site data and backups without proper authorization checks. This affects the plugin's core backup and migration functionality.
What an attacker can do
Read, modify, or delete site backups and data as a low-privilege authenticated user.
Potential impact on your site
Unauthorized users can access, alter, or destroy backups and site data, compromising site integrity and recovery options.
Conditions required to exploit
Attacker must have a valid user account on the site (low privilege level sufficient).
Key dates
External resources
Related vulnerabilities