CVE-2023-5576 is a critical sensitive information exposure vulnerability affecting the WPvivid Migration, Backup, Staging plugin for WordPress, versions up to and including 0.9.91. The vulnerability stems from Google Drive API secrets being stored in plaintext within publicly accessible plugin source code. With a CVSS score of 9.3 (CRITICAL), this vulnerability has a high attack complexity and could allow unauthenticated attackers to impersonate the WPVivid Google Drive account. This impersonation is possible if an attacker can trick a user into reauthenticating through social engineering or another vulnerability, leading to high confidentiality and integrity impacts. While there is no evidence of active exploitation (KEV: No) and no public exploit code (Metasploit, Nuclei, ExploitDB: None), the vulnerability has garnered significant community attention with 10 mentions, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.9.91CPE matchmatch criteria | cpe:2.3:a:wpvivid:migration\,_backup\,_staging:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.