Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54490 | The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the restore() and get_restore_progress() function in versions up to, and including, 0.9.94. This makes it possible for unauthenticated attackers to invoke these functions and obtain full file paths if they have access to a back-up ID. |
Fri, 10 Apr 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 08 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | WPvivid <= 0.9.94 - Missing Authorization |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:18:20.693Z
Reserved: 2023-08-30T14:15:50.559Z
Link: CVE-2023-4637
Updated: 2024-08-02T07:31:06.579Z
Status : Modified
Published: 2024-02-05T22:15:55.410
Modified: 2026-04-08T19:18:32.780
Link: CVE-2023-4637
No data.
OpenCVE Enrichment
No data.
EUVD