Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesWPvivid

WPvivid vulnerabilities

WPvivid has 17 known vulnerabilities in this database. The most recent published record is dated 4 Sep 2026.

Known vulnerabilities
17
Active installs
900,000+
Latest version
0.9.136
Last updated
28 Sep 2026
Most recent
4 Sep 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Path traversal
CVE-2026-82193
Medium 5.5Before 0.9.134Fixed in 0.9.1344 Sep 2026
Arbitrary file deletion
CVE-2026-82194
Medium 5.5Before 0.9.134Fixed in 0.9.1344 Sep 2026
SQL injection
CVE-2026-82182
Medium 4.1Before 0.9.133Fixed in 0.9.1332 Sep 2026
Path traversal
CVE-2026-19722
Medium 6.6Before 0.9.133Fixed in 0.9.13330 Aug 2026
Path traversal
CVE-2026-19725
Critical 9.1Before 0.9.131Fixed in 0.9.13116 Aug 2026
SQL injection
CVE-2026-17555
Medium 4.9Up to 0.9.131Fixed in a later version (latest 0.9.136)1 Aug 2026
Arbitrary file deletion
CVE-2025-12656
Low 3.8Up to 0.9.128Fixed in a later version (latest 0.9.136)6 Jun 2026
Remote code execution
CVE-2026-1357
Critical 9.8Up to 0.9.123Fixed in a later version (latest 0.9.136)11 Feb 2026
Arbitrary file deletion
CVE-2025-12654
Low 2.7Up to 0.9.120Fixed in a later version (latest 0.9.136)21 Dec 2025
Remote code execution
CVE-2025-5961
High 7.2Before 0.9.117Fixed in 0.9.1173 Jul 2025
Remote code execution
CVE-2024-13869
High 7.2Before 0.9.113Fixed in 0.9.11322 Feb 2025
PHP object injection
CVE-2024-10962
High 8.8Before 0.9.108Fixed in 0.9.10814 Nov 2024
Broken access control
CVE-2023-4637
Medium 4.3Up to 0.9.94Fixed in a later version (latest 0.9.136)5 Feb 2024
Cross-site scripting (XSS)
CVE-2023-5120
Medium 4.4Up to 0.9.89Fixed in a later version (latest 0.9.136)20 Oct 2023
Sensitive data exposure
CVE-2023-5576
High 8.0Up to 0.9.91Fixed in a later version (latest 0.9.136)20 Oct 2023
Path traversal
CVE-2023-4274
High 8.7Before 0.9.90Fixed in 0.9.9020 Oct 2023
PHP object injection
CVE-2022-2442
High 7.2Up to 0.9.74Fixed in a later version (latest 0.9.136)6 Sep 2022
Read the published descriptions
CVE-2026-82193, 4 Sep 2026
The WPvivid - Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied file name before using it to build a write path, allowing administrators to write files of permitted types to arbitrary locations on the server and to overwrite existing files. CVE record
CVE-2026-82194, 4 Sep 2026
The WPvivid - Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before using it in a file deletion routine, allowing administrators to delete arbitrary files on the server, including files outside the web root. CVE record
CVE-2026-82182, 2 Sep 2026
The WPvivid - Backup, Migration & Staging WordPress plugin before 0.9.133 does not sanitise a user supplied list of identifiers before using it in a SQL query, allowing administrators to perform SQL injection attacks. CVE record
CVE-2026-19722, 30 Aug 2026
The WPvivid - Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, allowing high privilege users such as administrators to write arbitrary files outside the intended restore directory, which can lead to code execution. CVE record
CVE-2026-19725, 16 Aug 2026
The WPvivid - Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an unauthenticated request before using it to build a log file path, allowing an attacker holding a site to site transfer key to create a log file in any existing writable directory of the site, including the web root. The file name always carries a fixed suffix and the contents are always the WPvivid - Backup, Migration & Staging WordPress plugin before 0.9.131's own log header, so only the location of the file is attacker controlled. CVE record
CVE-2026-17555, 1 Aug 2026
The WPvivid Backup & Migration plugin for WordPress is vulnerable to SQL Injection via the export_data parameter in versions up to, and including, 0.9.131. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. The values are received in prepare_export_post(), passed through sanitize_text_field() and stripslashes(), JSON-decoded, and the attacker-controlled JSON object keys are collected as $posts_ids without integer casting. They are stored in the export task options and later joined with commas and interpolated directly into a `WHERE ID IN (...)` clause inside a $wpdb->get_results() call in export_post_to_xml() (unquoted, numeric context), with no $wpdb->prepare() or esc_sql(). This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2025-12656, 6 Jun 2026
The Migration, Backup, Staging - WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in the delete_cancel_staging_site() function in all versions up to, and including, 0.9.128. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary folders on the server, which leads to a loss of data. CVE record
CVE-2026-1357, 11 Feb 2026
The Migration, Backup, Staging - WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions up to and including 0.9.123. This is due to improper error handling in the RSA decryption process combined with a lack of path sanitization when writing uploaded files. When the plugin fails to decrypt a session key using openssl_private_decrypt(), it does not terminate execution and instead passes the boolean false value to the phpseclib library's AES cipher initialization. The library treats this false value as a string of null bytes, allowing an attacker to encrypt a malicious payload using a predictable null-byte key. Additionally, the plugin accepts filenames from the decrypted payload without sanitization, enabling directory traversal to escape the protected backup directory. This makes it possible for unauthenticated attackers to upload arbitrary PHP files to publicly accessible directories and achieve Remote Code Execution via the wpvivid_action=send_to_site parameter. CVE record
CVE-2025-12654, 21 Dec 2025
The Migration, Backup, Staging - WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory creation in all versions up to, and including, 0.9.120. This is due to the check_filesystem_permissions() function not properly restricting the directories that can be created, or in what location. This makes it possible for authenticated attackers, with Administrator-level access and above, to create arbitrary directories. CVE record
CVE-2025-5961, 3 Jul 2025
The Migration, Backup, Staging - WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpvivid_upload_import_files' function in all versions up to, and including, 0.9.116. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. NOTE: Uploaded files are only accessible on WordPress instances running on the NGINX web server as the existing .htaccess within the target file upload folder prevents access on Apache servers. CVE record
CVE-2024-13869, 22 Feb 2025
The Migration, Backup, Staging - WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_files' function in all versions up to, and including, 0.9.112. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. NOTE: Uploaded files are only accessible on WordPress instances running on the NGINX web server as the existing .htaccess within the target file upload folder prevents access on Apache servers. CVE record
CVE-2024-10962, 14 Nov 2024
The Migration, Backup, Staging - WPvivid plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.9.107 via deserialization of untrusted input in the 'replace_row_data' and 'replace_serialize_data' functions. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code. An administrator must create a staging site to trigger the exploit. CVE record
CVE-2023-4637, 5 Feb 2024
The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the restore() and get_restore_progress() function in versions up to, and including, 0.9.94. This makes it possible for unauthenticated attackers to invoke these functions and obtain full file paths if they have access to a back-up ID. CVE record
CVE-2023-5120, 20 Oct 2023
The Migration, Backup, Staging - WPvivid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image file path parameter in versions up to, and including, 0.9.89 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2023-5576, 20 Oct 2023
The Migration, Backup, Staging - WPvivid plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 0.9.91 via Google Drive API secrets stored in plaintext in the publicly visible plugin source. This could allow unauthenticated attackers to impersonate the WPVivid Google Drive account via the API if they can trick a user into reauthenticating via another vulnerability or social engineering. CVE record
CVE-2023-4274, 20 Oct 2023
The Migration, Backup, Staging - WPvivid plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 0.9.89. This allows authenticated attackers with administrative privileges to delete the contents of arbitrary directories on the server, which can be a critical issue in a shared environments. CVE record
CVE-2022-2442, 6 Sep 2022
The Migration, Backup, Staging - WPvivid plugin for WordPress is vulnerable to deserialization of untrusted input via the 'path' parameter in versions up to, and including 0.9.74. This makes it possible for authenticated attackers with administrative privileges to call files using a PHAR wrapper that will deserialize and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload. CVE record

What to do if you run WPvivid

If you run WPvivid, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new WPvivid vulnerabilities

Free. We email you when a new vulnerability is published for WPvivid, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support