Reflected Cross-Site Scripting Vulnerability in WPvivid Backup Plugin for WordPress
CVE-2024-1383
6.1MEDIUM
What is CVE-2024-1383?
The WPvivid Backup for MainWP plugin for WordPress suffers from a reflected cross-site scripting issue due to inadequate input sanitization and output escaping. This vulnerability affects all versions up to and including 0.9.32. It allows unauthenticated attackers to inject arbitrary web scripts through the 'id' parameter, which can be executed on user pages if they are tricked into interacting with a malicious link. Proper measures should be implemented to avoid such security threats.
Affected Version(s)
WPvivid Backup for MainWP * <= 0.9.32