First published: Mon Feb 28 2022(Updated: )
The Migration, Backup, Staging WordPress plugin before 0.9.69 does not have authorisation when adding remote storages, and does not sanitise as well as escape a parameter from such unauthenticated requests before outputting it in admin page, leading to a Stored Cross-Site Scripting issue
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WPvivid Migration, Backup, Staging | <0.9.69 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24994 is a vulnerability in the Migration, Backup, Staging WordPress plugin before version 0.9.69 that allows for a Stored Cross-Site Scripting issue.
The severity of CVE-2021-24994 is medium with a CVSS score of 6.1.
CVE-2021-24994 affects the Wpvivid Migration, Backup, Staging WordPress plugin before version 0.9.69 by allowing unauthenticated users to add remote storages without authorization and potentially execute a stored cross-site scripting attack.
To fix CVE-2021-24994, upgrade to version 0.9.69 or later of the Migration, Backup, Staging WordPress plugin.
You can find more information about CVE-2021-24994 at the following reference link: [https://wpscan.com/vulnerability/ea74257a-f6b0-49e9-a81f-53c0eb81b1da](https://wpscan.com/vulnerability/ea74257a-f6b0-49e9-a81f-53c0eb81b1da).