CVE-2020-36842

HIGH EXPLOITED

WPvivid <0.9.35 - RCE

Title source: llm

Description

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the wpvivid_upload_import_files and wpvivid_upload_files AJAX actions that allows low-level authenticated attackers to upload zip files that can be subsequently extracted. This affects versions up to, and including 0.9.35.

Exploits (2)

nomisec WORKING POC
by Nxploited · remote-auth
https://github.com/Nxploited/CVE-2020-36842
github WORKING POC
by Boshe99 · pythonpoc
https://github.com/Boshe99/CVE-Exploits/tree/main/CVE-2020-36842

Scores

CVSS v3 8.8
EPSS 0.4522
EPSS Percentile 97.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

VulnCheck KEV 2024-10-15

Classification

CWE
CWE-434
Status published

Affected Products (1)

wpvivid/migration\,_backup\,_staging < 0.9.35

Timeline

Published Oct 16, 2024
Tracked Since Feb 18, 2026