← WordPress Vulnerabilities
WordPress security by component

WPvivid Backup and Migration

WPvivid Backup and Migration is a WordPress component with 11 published CVE records in this archive. The latest tracked vulnerability was published Jan 07, 2025; the highest CVE/CNA score is 9.8.

Plugin slug: migration-backup-staging

CVE-2024-56273: WPvivid Backup and Migration: A security weakness

WPvivid Backup and Migration is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedJan 07, 2025
Safe version guidanceSee mitigation notes
Safe version
Jan 07, 2025 CVE-2024-56273
WPvivid Backup and Migration: A security weakness
WPvivid Backup and Migration is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD9.8
Oct 16, 2024 CVE-2020-36842
Migration, Backup, Staging – WPvivid: Dangerous file upload
Migration, Backup, Staging – WPvivid is affected by dangerous file upload. Exploitation requires an authenticated WordPress account. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE8.8
NVDPending
Oct 16, 2024 CVE-2020-36835
Migration, Backup, Staging – WPvivid: Sensitive information exposure
Migration, Backup, Staging – WPvivid is affected by sensitive information exposure. Exploitation requires an authenticated WordPress account. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE4.9
NVD6.5
Oct 02, 2024 CVE-2024-7315
Migration, Backup, Staging: A security weakness
Migration, Backup, Staging is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending
Apr 12, 2024 CVE-2024-3054
Migration, Backup, Staging: Code execution
Migration, Backup, Staging is affected by code execution. Exploitation requires an authenticated WordPress account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.2
NVDPending
Feb 29, 2024 CVE-2024-1982
Migration, Backup, Staging – WPvivid: SQL injection
Migration, Backup, Staging – WPvivid is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE6.5
NVD9.1
Feb 29, 2024 CVE-2024-1981
Migration, Backup, Staging – WPvivid: SQL injection
Migration, Backup, Staging – WPvivid is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.1
Oct 20, 2023 CVE-2023-5121
Migration, Backup, Staging – WPvivid: Cross-site scripting
Migration, Backup, Staging – WPvivid is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVD4.8
Sep 16, 2022 CVE-2022-2863
Migration, Backup, Staging: A security weakness
Migration, Backup, Staging is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.9
NVD4.9
Apr 11, 2022 CVE-2022-0531
Migration, Backup, Staging: Cross-site scripting
Migration, Backup, Staging is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Feb 28, 2022 CVE-2021-24994
Migration, Backup, Staging: Cross-site scripting
Migration, Backup, Staging is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1