CVE-2020-36835: Migration, Backup, Staging – WPvivid <= 0.9.35 - Sensitive Information Disclosure
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a WordPress site's database due to missing capability checks on the wpajaxwpvividaddremote AJAX action that allows low-level authenticated attackers to send back-ups to a remote location of their choice for review. This affects versions up to, and including 0.9.35.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36835?
CVE-2020-36835 is classified as a medium severity vulnerability due to the risk of sensitive information disclosure.
How do I fix CVE-2020-36835?
To fix CVE-2020-36835, update the WPvivid Migration, Backup, Staging plugin to version 0.9.36 or later.
Who is affected by CVE-2020-36835?
Users of the WPvivid Migration, Backup, Staging plugin for WordPress with versions up to and including 0.9.35 are affected by CVE-2020-36835.
What kind of attack does CVE-2020-36835 expose?
CVE-2020-36835 exposes WordPress sites to low-level authenticated attackers who can exploit the vulnerability to access sensitive database information.
What component of WordPress does CVE-2020-36835 impact?
CVE-2020-36835 impacts the wp_ajax_wpvivid_add_remote AJAX action of the WPvivid Migration, Backup, Staging plugin.