Medium severity4.9NVD Advisory· Published Sep 16, 2022· Updated Jun 17, 2026
CVE-2022-2863
CVE-2022-2863
Description
The Migration, Backup, Staging WordPress plugin before 0.9.76 does not sanitise and validate a parameter before using it to read the content of a file, allowing high privilege users to read any file from the web server via a Traversal attack
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:wpvivid:migration\,_backup\,_staging:*:*:*:*:*:wordpress:*:*Range: <0.9.76
- WordPress/Migration, Backup, Staging WordPress plugindescription
- Range: <0.9.76
Patches
Vulnerability mechanics
References
3- packetstormsecurity.com/files/168616/WordPress-WPvivid-Backup-Path-Traversal.htmlnvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2022/Oct/0nvdExploitMailing ListThird Party Advisory
- wpscan.com/vulnerability/cb6a3304-2166-47a0-a011-4dcacaa133e5nvdExploitPatchThird Party Advisory
News mentions
0No linked articles in our index yet.