← volver
CVE-2023-5576

Migration, Backup, Staging – WPvivid <= 0.9.91 - Google Drive Client Secret Exposure

CVSS 8 HIGHEPSS 0.8%CWE-200
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8EPSS 0.8%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
20 oct 2023Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
The Migration, Backup, Staging - WPvivid plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 0.9.91 via Google Drive API secrets stored in plaintext in the publicly visible plugin source. This could allow unauthenticated attackers to impersonate the WPVivid Google Drive account via the API if they can trick a user into reauthenticating via another vulnerability or social engineering.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →