← Vulnerability feed

Vulnerability record · CVE-2024-3054 · published 12 April 2024

CVE-2024-3054: Wpvivid migration\ deserialization of untrusted data vulnerability

Wpvivid · Migration\

WPvivid Backup & Migration Plugin for WordPress is vulnerable to PHAR Deserialization in all versions up to, and including, 0.9.99 via deserialization of untrusted input at the wpvividstg_get_custom_exclude_path_free action. This is due to the plugin not providing sufficient path validation on the tree_node[node][id] parameter. This makes it possible for authenticated attackers, with admin-level access and above, to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

7.2 CVSS 3.1 High EPSS 42% · top 1.4% CWE-502 · Deserialization of untrusted data
7.2CVSS 3.1 base score
42%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

WPvivid Backup & Migration Plugin for WordPress is vulnerable to PHAR Deserialization in all versions up to, and including, 0.9.99 via deserialization of untrusted input at the wpvividstg_get_custom_exclude_path_free action. This is due to the plugin not providing sufficient path validation on the tree_node[node][id] parameter. This makes it possible for authenticated attackers, with admin-level access and above, to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-3054 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-56273Wpvivid migration\ missing authorization vulnerabilityMissing Authorization vulnerability in wpvividplugins WPvivid Backup and Migration wpvivid-backuprestore allows Accessing Functionality Not Properly …EPSS 0.40%9.3CVE-2023-5576Wpvivid migration\ information exposure vulnerabilityThe Migration, Backup, Staging - WPvivid plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 0.9.9…EPSS 0.75%9.1CVE-2024-1982Wpvivid migration\ missing authorization vulnerabilityThe Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the get_resto…EPSS 0.83%9.1CVE-2024-1981Wpvivid migration\ sql injection vulnerabilityThe Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to SQL Injection via the 'table_prefix' parameter in version 0.9.68 due t…EPSS 1.1%8.8CVE-2024-10962Wpvivid migration\ deserialization of untrusted data vulnerabilityThe Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.9.107 via…EPSS 0.65%8.8CVE-2020-36842Wpvivid migration\ unrestricted file upload vulnerabilityThe Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the wpvivi…EPSS 1.2%8.8CVE-2023-41243Wpvivid migration\ improper privilege management vulnerabilityImproper Privilege Management vulnerability in WPvivid Team WPvivid Backup and Migration allows Privilege Escalation.This issue affects WPvivid Backu…EPSS 0.71%7.5CVE-2024-7315Wpvivid migration\ vulnerabilityThe Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient randomness in the filename that is created when generating a b…EPSS 0.58%

Source: NIST National Vulnerability Database (record CVE-2024-3054), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.