cleantalk
Vulnerabilities and Security Researches

Migration, Backup, Staging – WPvivid, CVE-2021-24994

CVE, Research URL

CVE-2021-24994

Published on
Feb 28, 2022
Research Description
The Migration, Backup, Staging WordPress plugin before 0.9.69 does not have authorisation when adding remote storages, and does not sanitise as well as escape a parameter from such unauthenticated requests before outputting it in admin page, leading to a Stored Cross-Site Scripting issue
Affected versions
Min -, max 0.9.71.
Status
vulnerable