CVE-2020-36842: Migration, Backup, Staging – WPvivid <= 0.9.35 - Authenticated (Subscriber+) Arbitrary File Upload
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the wpvividuploadimportfiles and wpvividuploadfiles AJAX actions that allows low-level authenticated attackers to upload zip files that can be subsequently extracted. This affects versions up to, and including 0.9.35.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36842?
CVE-2020-36842 is considered a critical vulnerability that allows unauthorized file uploads.
How do I fix CVE-2020-36842?
To fix CVE-2020-36842, update the Wpvivid Migration, Backup, Staging plugin to the latest version above 0.9.35.
Who is affected by CVE-2020-36842?
CVE-2020-36842 affects users of the Wpvivid Migration, Backup, Staging plugin for WordPress versions up to 0.9.35.
What types of attacks can CVE-2020-36842 enable?
CVE-2020-36842 can enable low-level authenticated attackers to upload malicious zip files.
Is CVE-2020-36842 easy to exploit?
Yes, CVE-2020-36842 is relatively easy to exploit due to the missing capability checks in the affected plugin.