CVE-2024-7315: Wpvivid Migration, Backup, Staging
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
The Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient randomness in the filename that is created when generating a backup, which could be bruteforced by attackers to leak sensitive information about said backups.
Affected products
- Wpvivid Migration, Backup, Staging: before 0.9.106 (fixed in 0.9.106)
Published 2024-10-02. Last modified 2026-06-17.