← WordPress Vulnerabilities
WordPress security by component

Migration, Backup, Staging – WPvivid

Migration, Backup, Staging – WPvivid (wpvivid-backuprestore) is a WordPress plugin with 15 published CVE records in this archive. The latest tracked vulnerability was published Sep 02, 2026; the highest published CVSS base score is 9.8.

Plugin slug: wpvivid-backuprestore

CVE-2026-82182: WPvivid permits Administrator-level SQL injection

WPvivid before 0.9.133 places an administrator-supplied list of identifiers into a database query without adequate sanitization, allowing an Administrator to perform SQL injection.

PublishedSep 02, 2026
Known safe version0.9.133
Published vulnerabilities for wpvivid-backuprestore
Safe version
Sep 02, 2026 CVE-2026-82182
WPvivid permits Administrator-level SQL injection
WPvivid before 0.9.133 places an administrator-supplied list of identifiers into a database query without adequate sanitization, allowing an Administrator to perform SQL injection.
0.9.133
CVE4.1
NVDPending
Aug 16, 2026 CVE-2026-19725
WPvivid transfer logging permits authenticated path traversal
WPvivid Backup and Migration before 0.9.131 accepts attacker-controlled path data during a site-to-site transfer and uses it when creating a transfer log. A remote requester must possess a valid site-to-site transfer key, but can then traverse into any existing directory writable by PHP and create the plugin's fixed-name log file there. Only the location is controlled: the filename suffix and log header are fixed, and.
0.9.131
CVE9.1
NVDPending
Aug 01, 2026 CVE-2026-17555
WPvivid export task IDs permit Administrator SQL injection
WPvivid through 0.9.131 accepts export_data JSON object keys in prepare_export_post(), stores them as post IDs without integer casting, then joins them into an unquoted WHERE ID IN clause in export_post_to_xml(). An Administrator can inject SQL through those keys and extract database information.
> 0.9.131
CVE4.9
NVDPending
Jun 06, 2026 CVE-2025-12656
WPvivid — Backup, Migration & Staging: Arbitrary file deletion
WPvivid — Backup, Migration & Staging is affected by arbitrary file deletion. Exploitation requires an authenticated administrator account. A successful request can remove files outside the intended scope and may make the site unavailable. The published affected range is <= 0.9.128.
See mitigation notes
CVE3.8
NVDPending
Feb 11, 2026 CVE-2026-1357
Migration, Backup, Staging – WPvivid Backup & Migration: Dangerous file upload
Migration, Backup, Staging – WPvivid Backup & Migration is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE9.8
NVDPending
Dec 21, 2025 CVE-2025-12654
Migration, Backup, Staging – WPvivid Backup & Migration: A security weakness
Migration, Backup, Staging – WPvivid Backup & Migration is affected by a security weakness. Exploitation requires an authenticated administrator account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE2.7
NVDPending
Jul 03, 2025 CVE-2025-5961
Migration, Backup, Staging – WPvivid Backup & Migration: Dangerous file upload
Migration, Backup, Staging – WPvivid Backup & Migration is affected by dangerous file upload. Exploitation requires an authenticated administrator account. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE7.2
NVDPending
Nov 14, 2024 CVE-2024-10962
Migration, Backup, Staging – WPvivid: Code execution
Migration, Backup, Staging – WPvivid is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVDPending
May 17, 2024 CVE-2023-41243
WPvivid Backup and Migration: Privilege escalation or authentication bypass
WPvivid Backup and Migration is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVD8.8
Feb 05, 2024 CVE-2023-4637
WPvivid: A security weakness
WPvivid is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD5.3
Oct 20, 2023 CVE-2023-5576
Migration, Backup, Staging - WPvivid: Sensitive information exposure
Migration, Backup, Staging - WPvivid is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE8.0
NVD9.3
Oct 20, 2023 CVE-2023-5120
Migration, Backup, Staging – WPvivid: Cross-site scripting
Migration, Backup, Staging – WPvivid is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVD4.8
Oct 20, 2023 CVE-2023-4274
Migration, Backup, Staging – WPvivid: Filesystem traversal
Migration, Backup, Staging – WPvivid is affected by filesystem traversal. Exploitation requires an authenticated WordPress account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.7
NVD6.5
Sep 06, 2022 CVE-2022-2442
Migration, Backup, Staging – WPvivid: Code execution
Migration, Backup, Staging – WPvivid is affected by code execution. Exploitation requires an authenticated WordPress account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.2
NVD7.2
Apr 11, 2022 CVE-2022-27844
Wpvivid Backuprestore: Filesystem traversal
Wpvivid Backuprestore is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE2.7
NVD7.5