CVE-2023-4637: WPvivid <= 0.9.94 - Missing Authorization
The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the restore() and getrestoreprogress() function in versions up to, and including, 0.9.94. This makes it possible for unauthenticated attackers to invoke these functions and obtain full file paths if they have access to a back-up ID.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-4637?
CVE-2023-4637 has a high severity due to the potential for unauthorized access to sensitive data.
How do I fix CVE-2023-4637?
To fix CVE-2023-4637, update the WPvivid plugin to version 0.9.95 or later.
What are the affected versions of the WPvivid plugin in CVE-2023-4637?
The affected versions of the WPvivid plugin in CVE-2023-4637 are up to and including version 0.9.94.
Who can be affected by CVE-2023-4637?
Unauthenticated attackers can be affected by CVE-2023-4637 by exploiting the vulnerability to access restricted functions.
What functions are vulnerable in CVE-2023-4637?
The restore() and get_restore_progress() functions are vulnerable in CVE-2023-4637 due to a missing capability check.