CVE-2024-1383: WPvivid Backup for MainWP <= 0.9.32 - Reflected Cross-Site Scripting
The WPvivid Backup for MainWP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in all versions up to, and including, 0.9.32 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE-2024-35664 is likely a duplicate of this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1383?
CVE-2024-1383 is considered a high severity vulnerability due to the potential for unauthenticated attackers to exploit it.
How do I fix CVE-2024-1383?
To fix CVE-2024-1383, update the WPvivid Backup for MainWP plugin to version 0.9.33 or later.
Who is affected by CVE-2024-1383?
CVE-2024-1383 affects all versions of WPvivid Backup for MainWP up to and including 0.9.32.
What type of vulnerability is CVE-2024-1383?
CVE-2024-1383 is a Reflected Cross-Site Scripting vulnerability.
Can CVE-2024-1383 be exploited remotely?
Yes, CVE-2024-1383 can be exploited remotely by unauthenticated attackers through the 'id' parameter.