Stored Cross-Site Scripting Vulnerability in WPvivid Plugin for WordPress
CVE-2023-5120
4.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 October 2023
What is CVE-2023-5120?
The WPvivid Backup Plugin for WordPress is prone to a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping in the image file path parameter. This flaw allows authenticated attackers with administrative access to execute arbitrary scripts on affected pages, potentially compromising user sessions and enabling further attacks. It is critical for users running versions up to and including 0.9.89 to apply updates promptly to mitigate risks.
Affected Version(s)
Migration, Backup, Staging – WPvivid * <= 0.9.89