cve/2023/CVE-2023-4637.md
2024-05-25 21:48:12 +02:00

18 lines
906 B
Markdown

### [CVE-2023-4637](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4637)
![](https://img.shields.io/static/v1?label=Product&message=Migration%2C%20Backup%2C%20Staging%20%E2%80%93%20WPvivid&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=*%3C%3D%200.9.94%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-862%20Missing%20Authorization&color=brighgreen)
### Description
The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the restore() and get_restore_progress() function in versions up to, and including, 0.9.94. This makes it possible for unauthenticated attackers to invoke these functions and obtain full file paths if they have access to a back-up ID.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/fkie-cad/nvd-json-data-feeds