CyberRota Analysis
AI-GeneratedThe WPvivid Backup, Migration & Staging plugin for WordPress versions prior to 0.9.134 is vulnerable due to insufficient validation of user-supplied file names, enabling administrators to write files to arbitrary server locations and overwrite existing files. This flaw poses a significant risk of unauthorized file manipulation, which could lead to data loss or further exploitation of the server. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential security risks.
Original NVD Description
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied file name before using it to build a write path, allowing administrators to write files of permitted types to arbitrary locations on the server and to overwrite existing files.