Input validation vulnerability in Migration, Backup, Staging – WPvivid Backup & Migration 0.9.116

The WPvivid Backup & Migration plugin for WordPress has a security vulnerability that allows attackers to upload any type of file without restriction. This can be done by users with Administrator-level access or higher, and may result in the ability to execute code remotely. It is important to note that this vulnerability only affects WordPress sites using the NGINX web server, as those using Apache are protected by the .htaccess file in the target upload folder.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.