CVE-2024-56273
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jan 7, 2025
Updated: Feb 25, 2025
CWE ID 862
Summary
CVE-2024-56273 is a Missing Authorization vulnerability affecting WPvivid Backup and Migration. The plugin, from versions n/a through 0.9.106, fails to properly constrain access to certain functionality. As a result, unauthorized users may gain access to restricted areas and perform actions they should not be able to. This poses a significant risk to websites using the WPvivid Backup and Migration plugin and should be addressed promptly by updating to a patched version.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Wpvivid Migration, Backup, Staging