CVE-2021-24994: WPvivid Backup and Migration Plugin < 0.9.69 - Unauthenticated Stored Cross-Site Scripting
The Migration, Backup, Staging WordPress plugin before 0.9.69 does not have authorisation when adding remote storages, and does not sanitise as well as escape a parameter from such unauthenticated requests before outputting it in admin page, leading to a Stored Cross-Site Scripting issue
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24994?
CVE-2021-24994 is a vulnerability in the Migration, Backup, Staging WordPress plugin before version 0.9.69 that allows for a Stored Cross-Site Scripting issue.
What is the severity of CVE-2021-24994?
The severity of CVE-2021-24994 is medium with a CVSS score of 6.1.
How does CVE-2021-24994 affect the Wpvivid Migration, Backup, Staging WordPress plugin?
CVE-2021-24994 affects the Wpvivid Migration, Backup, Staging WordPress plugin before version 0.9.69 by allowing unauthenticated users to add remote storages without authorization and potentially execute a stored cross-site scripting attack.
How can I fix CVE-2021-24994?
To fix CVE-2021-24994, upgrade to version 0.9.69 or later of the Migration, Backup, Staging WordPress plugin.
Where can I find more information about CVE-2021-24994?
You can find more information about CVE-2021-24994 at the following reference link: [https://wpscan.com/vulnerability/ea74257a-f6b0-49e9-a81f-53c0eb81b1da](https://wpscan.com/vulnerability/ea74257a-f6b0-49e9-a81f-53c0eb81b1da).