Access violation vulnerability in Migration, Backup, Staging – WPvivid 0.9.91

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 0.9.91. This vulnerability exposes the Google Drive API secrets stored in plaintext in the publicly visible plugin source. This means that unauthenticated attackers can gain access to the WPVivid Google Drive account through the API if they can trick a user into reauthenticating with another vulnerability or by using social engineering to get the user to provide their credentials.

Detected in:

Migration, Backup, Staging – WPvivid fixed vulnerable versions: >= * <= 0.9.91

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.