Description
WordPress Plugin Migration, Backup, Staging-WPvivid is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently add a new remote storage location and set it as the default backup location. WordPress Plugin Migration, Backup, Staging-WPvivid version 0.9.35 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 0.9.36 or latest
References
Related Vulnerabilities
WordPress 3.7.x Multiple Vulnerabilities (3.7 - 3.7.36)
WordPress 4.1.x Possible SQL Injection Vulnerability (4.1 - 4.1.19)
MySQL CVE-2015-4761 Vulnerability (CVE-2015-4761)
WordPress Plugin Video Gallery /w YouTube, Vimeo Arbitrary File Upload (8.48)
WordPress Plugin Flow-Flow Social Stream Unspecified Vulnerability (3.0.71)