CVE-2022-2863
WPvivid Backup < 0.9.76 - Admin+ Arbitrary File Read
Record summary
CVE-2022-2863 has a selected CVSS score of 4.9 (medium); EIP currently links 1 Nuclei template.
Description
The Migration, Backup, Staging WordPress plugin before 0.9.76 does not sanitise and validate a parameter before using it to read the content of a file, allowing high privilege users to read any file from the web server via a Traversal attack
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Migration, Backup, Staging – WPvivid | CVE List | 0.9.76 to < 0.9.76 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress WPvivid Backup <0.9.76 - Local File InclusionCVSS 4.9
WordPress WPvivid Backup version 0.9.76 is vulnerable to local file inclusion because the plugin does not sanitize and validate a parameter before using it to read the content of a file, allowing high privilege users to read any file from the web server.
Impact
Successful exploitation of this vulnerability can lead to unauthorized access to sensitive files, remote code execution, and potential compromise of the entire WordPress installation.
Remediation
Upgrade to version 0.9.76 or later.
Source: ProjectDiscovery