CVE-2024-1982 affects the Migration, Backup, Staging – WPvivid plugin for WordPress, specifically versions up to and including 0.9.68. The vulnerability stems from a missing capability check in the get_restore_progress() and restore() functions, allowing unauthorized access. This critical vulnerability, rated 9.1 CVSS, enables unauthenticated attackers to perform SQL injection or trigger a Denial of Service. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion with 10 mentions, indicating awareness and potential interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.9.68CPE matchmatch criteria | cpe:2.3:a:wpvivid:migration\,_backup\,_staging:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.