Reflected XSS Vulnerability in WPvivid Backup for MainWP
CVE-2024-35664

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
4 June 2024

What is CVE-2024-35664?

A reflected Cross-site Scripting (XSS) vulnerability has been discovered in WPvivid Backup for MainWP, developed by WPvivid Team. This issue arises from improper input sanitization, allowing attackers to inject malicious scripts that can be executed in the context of a user's browser. This vulnerability has implications for user data security, as it can lead to session hijacking, redirection to malicious sites, or theft of sensitive information. All users utilizing versions of WPvivid Backup for MainWP up to 0.9.32 are urged to take immediate action.

Affected Version(s)

WPvivid Backup for MainWP 0 <= 0.9.32

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yudistira Arya (Patchstack Alliance)
.