CVE-2021-24994
28.02.2022, 09:15
The Migration, Backup, Staging WordPress plugin before 0.9.69 does not have authorisation when adding remote storages, and does not sanitise as well as escape a parameter from such unauthenticated requests before outputting it in admin page, leading to a Stored Cross-Site Scripting issue
Vendor | Product | Version |
---|---|---|
wpvivid | migration\,_backup\,_staging | 𝑥 < 0.9.69 |
𝑥
= Vulnerable software versions