Record summary

CVE-2022-2863 has a selected CVSS score of 4.9 (medium); EIP currently links 1 Nuclei template.

Description

The Migration, Backup, Staging WordPress plugin before 0.9.76 does not sanitise and validate a parameter before using it to read the content of a file, allowing high privilege users to read any file from the web server via a Traversal attack

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Migration, Backup, Staging – WPvivid

CVE List0.9.76 to < 0.9.76affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress WPvivid Backup <0.9.76 - Local File InclusionCVSS 4.9

WordPress WPvivid Backup version 0.9.76 is vulnerable to local file inclusion because the plugin does not sanitize and validate a parameter before using it to read the content of a file, allowing high privilege users to read any file from the web server.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access to sensitive files, remote code execution, and potential compromise of the entire WordPress installation.

Remediation

Upgrade to version 0.9.76 or later.

WeaknessesCWE-22
Authorstehtbl
Template tagscvecve2022wpwpscanseclistspacketstormauthenticatedlfiwordpresswp-pluginwpvividvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:wpvivid:migration\,_backup\,_staging:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

4