Migration, Backup, Staging – WPvivid <= 0.9.91 - Google Drive Client Secret Exposure
Vulnerability Description
The Migration, Backup, Staging - WPvivid plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 0.9.91 via Google Drive API secrets stored in plaintext in the publicly visible plugin source. This could allow unauthenticated attackers to impersonate the WPVivid Google Drive account via the API if they can trick a user into reauthenticating via another vulnerability or social engineering.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-5576
Credits & Attribution
No credits recorded in the NVD database.
References
More from wpvividplugins
View All →Affected Vendor
wpvividplugins
View all reports →