plugin

Wpvivid Backuprestore Vulnerabilities

65 known security issues reported for the Wpvivid Backuprestore WordPress plugin. Most recent disclosed Aug 20, 2026.

2 critical 11 high 14 medium 2 low

Running Wpvivid Backuprestore on your site? Check whether your installed version is affected.

Scan your site free

WPvivid — Backup, Migration & Staging < 0.9.131 - Unauthenticated Path Traversal

high

The WPvivid — Backup, Migration & Staging plugin for WordPress is vulnerable to Path Traversal in all versions up to 0.9.131. This is due to insufficient validation of a user supplied path. This makes it possible for unauthenticated attackers to access files and directories outside of the intended directory.

CVSS:
7.5
Affected:
up to 0.9.131
Fixed in:
0.9.131
Disclosed:
Aug 20, 2026

CVE-2026-19725 on NVD →

WPvivid <= 0.9.131 - Authenticated (Administrator+) SQL Injection via 'export_data' Parameter

medium

The WPvivid Backup & Migration plugin for WordPress is vulnerable to SQL Injection via the export_data parameter in versions up to, and including, 0.9.131. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. The values are received in prepare...

CVSS:
4.9
Affected:
up to 0.9.131
Fixed in:
0.9.132
Disclosed:
Jul 31, 2026

CVE-2026-17555 on NVD →

Migration, Backup, Staging – WPvivid Backup & Migration <= 0.9.128 - Authenticated (Admin+) Arbitrary Directory Deletion

low

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in the delete_cancel_staging_site() function in all versions up to, and including, 0.9.128. This makes it possible for authenticated attackers, with Adm...

CVSS:
3.8
Affected:
up to 0.9.128
Fixed in:
0.9.129
Disclosed:
Jun 5, 2026

CVE-2025-12656 on NVD →

Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload

critical

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions up to and including 0.9.123. This is due to improper error handling in the RSA decryption process combined with a lack of path sanitization when writing uploaded files. Whe...

CVSS:
9.8
Affected:
up to 0.9.123
Fixed in:
0.9.124
Disclosed:
Feb 10, 2026

CVE-2026-1357 on NVD →

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] <= 0.9.120 (unfixed)

unknown

[en] The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory creation in all versions up to, and including, 0.9.120. This is due to the check_filesystem_permissions() function not properly restricting the directories that can be created, or in what location....

Affected:
up to 0.9.120
Fix:
No patched version reported
Disclosed:
Dec 21, 2025

CVE-2025-12654 on NVD →

Migration, Backup, Staging – WPvivid Backup & Migration <= 0.9.120 - Authenticated (Admin+) Arbitrary Directory Creation

low

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory creation in all versions up to, and including, 0.9.120. This is due to the check_filesystem_permissions() function not properly restricting the directories that can be created, or in what location. This...

CVSS:
2.7
Affected:
up to 0.9.120
Fixed in:
0.9.121
Disclosed:
Dec 20, 2025

CVE-2025-12654 on NVD →

Migration, Backup, Staging – WPvivid Backup & Migration <= 0.9.116 - Authenticated (Administrator+) Arbitrary File Upload

high

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpvivid_upload_import_files' function in all versions up to, and including, 0.9.116. This makes it possible for authenticated attackers, with Administrator...

CVSS:
7.2
Affected:
up to 0.9.116
Fixed in:
0.9.117
Disclosed:
Jul 3, 2025

CVE-2025-5961 on NVD →

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.113

unknown

[en] The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_files' function in all versions up to, and including, 0.9.112. This makes it possible for authenticated attackers, with Administrator-level acc...

Affected:
up to 0.9.113
Fixed in:
0.9.113
Disclosed:
Feb 22, 2025

CVE-2024-13869 on NVD →

Migration, Backup, Staging – WPvivid <= 0.9.112 - Authenticated (Admin+) Arbitrary File Upload via wpvivid_upload_file

high

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_files' function in all versions up to, and including, 0.9.112. This makes it possible for authenticated attackers, with Administrator-level access a...

CVSS:
7.2
Affected:
up to 0.9.112
Fixed in:
0.9.113
Disclosed:
Feb 21, 2025

CVE-2024-13869 on NVD →

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.107

unknown

[en] Missing Authorization vulnerability in WPvivid Backup & Migration WPvivid Backup and Migration allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPvivid Backup and Migration: from n/a through 0.9.106.

Affected:
up to 0.9.107
Fixed in:
0.9.107
Disclosed:
Jan 7, 2025

CVE-2024-56273 on NVD →

WPvivid Backup and Migration <= 0.9.106 - Missing Authorization

medium

The WPvivid Backup and Migration plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the handle_auth_actions() function in versions up to, and including, 0.9.106. This makes it possible for unauthenticated attackers to connect their dropbox account.

CVSS:
5.3
Affected:
up to 0.9.106
Fixed in:
0.9.107
Disclosed:
Jan 3, 2025

CVE-2024-56273 on NVD →

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.108

unknown

[en] The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.9.107 via deserialization of untrusted input in the 'replace_row_data' and 'replace_serialize_data' functions. This makes it possible for unauthenticated attackers to inject a...

Affected:
up to 0.9.108
Fixed in:
0.9.108
Disclosed:
Nov 14, 2024

CVE-2024-10962 on NVD →

Migration, Backup, Staging – WPvivid <= 0.9.107 - Unauthenticated PHP Object Injection

high

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.9.107 via deserialization of untrusted input in the 'replace_row_data' and 'replace_serialize_data' functions. This makes it possible for unauthenticated attackers to inject a PHP...

CVSS:
8.8
Affected:
up to 0.9.107
Fixed in:
0.9.108
Disclosed:
Nov 13, 2024

CVE-2024-10962 on NVD →

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.36

unknown

[en] The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a WordPress site's database due to missing capability checks on the wp_ajax_wpvivid_add_remote AJAX action that allows low-level authenticated attackers to send back-ups to a remote location of their...

Affected:
up to 0.9.36
Fixed in:
0.9.36
Disclosed:
Oct 16, 2024

CVE-2020-36835 on NVD →

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.36

unknown

[en] The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the wpvivid_upload_import_files and wpvivid_upload_files AJAX actions that allows low-level authenticated attackers to upload zip files that can be subsequently extracted. This...

Affected:
up to 0.9.36
Fixed in:
0.9.36
Disclosed:
Oct 16, 2024

CVE-2020-36842 on NVD →

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.106

unknown

[en] The Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient randomness in the filename that is created when generating a backup, which could be bruteforced by attackers to leak sensitive information about said backups.

Affected:
up to 0.9.106
Fixed in:
0.9.106
Disclosed:
Oct 2, 2024

CVE-2024-7315 on NVD →

Migration, Backup, Staging – WPvivid <= 0.9.105 - Sensitive Information Exposure

high

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 0.9.105. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data by brute-forcing backup file names.

CVSS:
7.5
Affected:
up to 0.9.105
Fixed in:
0.9.106
Disclosed:
Sep 11, 2024

CVE-2024-7315 on NVD →

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.91

unknown

[en] Improper Privilege Management vulnerability in WPvivid Team WPvivid Backup and Migration allows Privilege Escalation.This issue affects WPvivid Backup and Migration: from n/a through 0.9.90.

Affected:
up to 0.9.91
Fixed in:
0.9.91
Disclosed:
May 17, 2024

CVE-2023-41243 on NVD →

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.100

unknown

[en] WPvivid Backup & Migration Plugin for WordPress is vulnerable to PHAR Deserialization in all versions up to, and including, 0.9.99 via deserialization of untrusted input at the wpvividstg_get_custom_exclude_path_free action. This is due to the plugin not providing sufficient path validation on the tree_node[node][...

Affected:
up to 0.9.100
Fixed in:
0.9.100
Disclosed:
Apr 12, 2024

CVE-2024-3054 on NVD →

WPvivid Backup & Migration Plugin <= 0.9.99 - Authenticated (Admin+) PHAR Deserialization

high

WPvivid Backup & Migration Plugin for WordPress is vulnerable to PHAR Deserialization in all versions up to, and including, 0.9.99 via deserialization of untrusted input at the wpvividstg_get_custom_exclude_path_free action. This is due to the plugin not providing sufficient path validation on the tree_node[node][id] p...

CVSS:
7.2
Affected:
up to 0.9.99
Fixed in:
0.9.100
Disclosed:
Apr 11, 2024

CVE-2024-3054 on NVD →

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.69

unknown

[en] The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the get_restore_progress() and restore() functions in all versions up to, and including, 0.9.68. This makes it possible for unauthenticated attackers to exploit a SQL injection vu...

Affected:
up to 0.9.69
Fixed in:
0.9.69
Disclosed:
Feb 29, 2024

CVE-2024-1982 on NVD →

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.69

unknown

[en] The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to SQL Injection via the 'table_prefix' parameter in version 0.9.68 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attac...

Affected:
up to 0.9.69
Fixed in:
0.9.69
Disclosed:
Feb 29, 2024

CVE-2024-1981 on NVD →

WPvivid Backup and Migration <= 0.9.68 - Unauthenticated SQL Injection

critical

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to SQL Injection via the 'table_prefix' parameter in version 0.9.68 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers...

CVSS:
9.8
Affected:
0.9.68 – 0.9.68
Fixed in:
0.9.69
Disclosed:
Feb 28, 2024

CVE-2024-1981 on NVD →

WPvivid Backup and Migration <= 0.9.68 - Missing Authorization

medium

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the get_restore_progress() and restore() functions in all versions up to, and including, 0.9.68. This makes it possible for unauthenticated attackers to exploit a SQL injection vulnera...

CVSS:
6.5
Affected:
up to 0.9.68
Fixed in:
0.9.69
Disclosed:
Feb 28, 2024

CVE-2024-1982 on NVD →

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.95

unknown

[en] The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the restore() and get_restore_progress() function in versions up to, and including, 0.9.94. This makes it possible for unauthenticated attackers to invoke these functions and obtain full file paths if...

Affected:
up to 0.9.95
Fixed in:
0.9.95
Disclosed:
Feb 5, 2024

CVE-2023-4637 on NVD →

WPvivid <= 0.9.94 - Missing Authorization

medium

The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the restore() and get_restore_progress() function in versions up to, and including, 0.9.94. This makes it possible for unauthenticated attackers to invoke these functions and obtain full file paths if they...

CVSS:
4.3
Affected:
up to 0.9.94
Fixed in:
0.9.95
Disclosed:
Jan 19, 2024

CVE-2023-4637 on NVD →

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.90

unknown

[en] The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings (the backup path parameter) in versions up to, and including, 0.9.89 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with adm...

Affected:
up to 0.9.90
Fixed in:
0.9.90
Disclosed:
Oct 20, 2023

CVE-2023-5121 on NVD →

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.92

unknown

[en] The Migration, Backup, Staging - WPvivid plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 0.9.91 via Google Drive API secrets stored in plaintext in the publicly visible plugin source. This could allow unauthenticated attackers to impersonate the WPVivid Google...

Affected:
up to 0.9.92
Fixed in:
0.9.92
Disclosed:
Oct 20, 2023

CVE-2023-5576 on NVD →

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.90

unknown

[en] The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image file path parameter in versions up to, and including, 0.9.89 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative pr...

Affected:
up to 0.9.90
Fixed in:
0.9.90
Disclosed:
Oct 20, 2023

CVE-2023-5120 on NVD →

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.90

unknown

[en] The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 0.9.89. This allows authenticated attackers with administrative privileges to delete the contents of arbitrary directories on the server, which can be a critical issue in a shared en...

Affected:
up to 0.9.90
Fixed in:
0.9.90
Disclosed:
Oct 20, 2023

CVE-2023-4274 on NVD →

Migration, Backup, Staging – WPvivid <= 0.9.91 - Google Drive Client Secret Exposure

high

The Migration, Backup, Staging - WPvivid plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 0.9.91 via Google Drive API secrets stored in plaintext in the publicly visible plugin source. This could allow unauthenticated attackers to impersonate the WPVivid Google Driv...

CVSS:
8
Affected:
up to 0.9.91
Fixed in:
0.9.92
Disclosed:
Oct 13, 2023

CVE-2023-5576 on NVD →

Migration, Backup, Staging – WPvivid <= 0.9.89 - Authenticated (Administrator+) Arbitrary Directory Deletion via Path Traversal

high

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 0.9.89. This allows authenticated attackers with administrative privileges to delete the contents of arbitrary directories on the server, which can be a critical issue in a shared environ...

CVSS:
8.7
Affected:
0.9.89 – 0.9.89
Fixed in:
0.9.90
Disclosed:
Sep 22, 2023

CVE-2023-4274 on NVD →

Migration, Backup, Staging – WPvivid <= 0.9.89 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings (the backup path parameter) in versions up to, and including, 0.9.89 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administ...

CVSS:
4.4
Affected:
up to 0.9.89
Fixed in:
0.9.90
Disclosed:
Sep 22, 2023

CVE-2023-5121 on NVD →

Migration, Backup, Staging – WPvivid <= 0.9.89 - Authenticated Stored Cross-Site Scripting

medium

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image file path parameter in versions up to, and including, 0.9.89 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privile...

CVSS:
4.4
Affected:
up to 0.9.89
Fixed in:
0.9.90
Disclosed:
Sep 22, 2023

CVE-2023-5120 on NVD →

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.91

unknown

Update the WordPress WPvivid Backup and Migration plugin to the latest available version (at least 0.9.91). Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress WPvivid Backup and Migration Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, a...

Affected:
up to 0.9.91
Fixed in:
0.9.91
Disclosed:
Sep 13, 2023

WPvivid Backup Plugin <= 0.9.90 - Missing Authorization via 'start_staging' and 'get_staging_progress'

high

The WPvivid Backup Plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the 'start_staging' and 'get_staging_progress' functions in versions up to, and including, 0.9.90. This makes it possible for authenticated attackers to create new staging s...

CVSS:
8.3
Affected:
up to 0.9.91
Fixed in:
0.9.91
Disclosed:
Sep 12, 2023

CVE-2023-41243 on NVD →

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.91

unknown

The WPvivid Backup Plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the 'start_staging' and 'get_staging_progress' functions in versions up to, and including, 0.9.90. This makes it possible for authenticated attackers to create new staging s...

Affected:
up to 0.9.91
Fixed in:
0.9.91
Disclosed:
Sep 12, 2023

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.76

unknown

[en] The Migration, Backup, Staging WordPress plugin before 0.9.76 does not sanitise and validate a parameter before using it to read the content of a file, allowing high privilege users to read any file from the web server via a Traversal attack

Affected:
up to 0.9.76
Fixed in:
0.9.76
Disclosed:
Sep 16, 2022

CVE-2022-2863 on NVD →

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.76

unknown

[en] The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to deserialization of untrusted input via the 'path' parameter in versions up to, and including 0.9.74. This makes it possible for authenticated attackers with administrative privileges to call files using a PHAR wrapper that will deseri...

Affected:
up to 0.9.76
Fixed in:
0.9.76
Disclosed:
Sep 6, 2022

CVE-2022-2442 on NVD →

WPvivid Backup 0.9.76 - Authenticated (Administrator+) Arbitrary File Deletion

medium

The WPvivid Backup plugin for WordPress is vulnerable to Path Traversal in version 0.9.76 due to a newly introduced delete_upload_incomplete_backup AJAX action. This allows administrator-level attackers to delete arbitrary files on the server.

CVSS:
6.5
Affected:
0.9.76 – 0.9.76
Fixed in:
0.9.77
Disclosed:
Aug 29, 2022

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.77

unknown

Authenticated Arbitrary File Deletion vulnerability discovered by WPScan in WordPress WPvivid Backup plugin (versions 0.9.76). Update the WordPress WPvivid Backup and Migration plugin to the latest available version (at least 0.9.77).

Affected:
up to 0.9.77
Fixed in:
0.9.77
Disclosed:
Aug 29, 2022

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.77

unknown

The WPvivid Backup plugin for WordPress is vulnerable to Path Traversal in version 0.9.76 due to a newly introduced delete_upload_incomplete_backup AJAX action. This allows administrator-level attackers to delete arbitrary files on the server.

Affected:
up to 0.9.77
Fixed in:
0.9.77
Disclosed:
Aug 29, 2022

Migration, Backup, Staging – WPvivid <= 0.9.75 - Authenticated (Administrator+) Path Traversal

medium

The WPvivid backup plugin for WordPress is vulnerable to arbitrary file read due to missing parameter sanitization and validation on the 'file_name' parameter in versions up to, and including, 0.9.75. This makes it possible for authenticated attackers, with administrator level permissions and above, to access arbitrar...

CVSS:
6.5
Affected:
up to 0.9.75
Fixed in:
0.9.76
Disclosed:
Aug 22, 2022

CVE-2022-2863 on NVD →

Migration, Backup, Staging – WPvivid <= 0.9.75 - Authenticated (Admin+) Directory Traversal

medium

The WPvivid plugin for WordPress is vulnerable to directory traversal in versions up to, and including, 0.9.75. This allows authenticated users with administrative privileges to download arbitrary files on the server, including sensitive configuration files, though the file size must be successfully guessed in order to...

CVSS:
6
Affected:
up to 0.9.75
Fixed in:
0.9.76
Disclosed:
Aug 16, 2022

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.76

unknown

The WPvivid plugin for WordPress is vulnerable to directory traversal in versions up to, and including, 0.9.75. This allows authenticated users with administrative privileges to download arbitrary files on the server, including sensitive configuration files, though the file size must be successfully guessed in order to...

Affected:
up to 0.9.76
Fixed in:
0.9.76
Disclosed:
Aug 16, 2022

Migration, Backup, Staging – WPvivid <= 0.9.74 - Authenticated (Admin+) PHAR Deserialization

high

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to deserialization of untrusted input via the 'path' parameter in versions up to, and including 0.9.74. This makes it possible for authenticated attackers with administrative privileges to call files using a PHAR wrapper that will deserialize...

CVSS:
7.2
Affected:
up to 0.9.74
Fixed in:
0.9.75
Disclosed:
Aug 10, 2022

CVE-2022-2442 on NVD →

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.70

unknown

[en] The Migration, Backup, Staging WordPress plugin before 0.9.70 does not sanitise and escape the sub_page parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting

Affected:
up to 0.9.70
Fixed in:
0.9.70
Disclosed:
Apr 11, 2022

CVE-2022-0531 on NVD →

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.71

unknown

[en] Arbitrary File Read vulnerability in WPvivid Team Migration, Backup, Staging – WPvivid (WordPress plugin) versions <= 0.9.70

Affected:
up to 0.9.71
Fixed in:
0.9.71
Disclosed:
Apr 11, 2022

CVE-2022-27844 on NVD →

Migration, Backup, Staging – WPvivid <= 0.9.70 - Authenticated Arbitrary File Read

medium

Arbitrary File Read vulnerability in WPvivid Team Migration, Backup, Staging – WPvivid (WordPress plugin) versions <= 0.9.70

CVSS:
4.9
Affected:
up to 0.9.70
Fixed in:
0.9.71
Disclosed:
Apr 7, 2022

CVE-2022-27844 on NVD →

Migration, Backup, Staging – WPvivid <= 0.9.69 - Reflected Cross-Site Scripting via sub_page Parameter

medium

The Migration, Backup, Staging WordPress plugin before 0.9.70 does not sanitise and escape the sub_page parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVSS:
6.1
Affected:
up to 0.9.70
Fixed in:
0.9.70
Disclosed:
Mar 21, 2022

CVE-2022-0531 on NVD →

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.71

unknown

[en] The Migration, Backup, Staging WordPress plugin before 0.9.69 does not have authorisation when adding remote storages, and does not sanitise as well as escape a parameter from such unauthenticated requests before outputting it in admin page, leading to a Stored Cross-Site Scripting issue

Affected:
up to 0.9.71
Fixed in:
0.9.71
Disclosed:
Feb 28, 2022

CVE-2021-24994 on NVD →

Migration, Backup, Staging – WPvivid <= 0.9.68 - Unauthenticated Stored Cross-Site Scripting

medium

The Migration, Backup, Staging – WPvivid plugin before 0.9.69 does not have authorisation when adding remote storages, and does not sanitise as well as escape a parameter from such unauthenticated requests before outputting it in admin page, leading to a Stored Cross-Site Scripting issue

CVSS:
6.1
Affected:
up to 0.9.69
Fixed in:
0.9.69
Disclosed:
Jan 31, 2022

CVE-2021-24994 on NVD →

Migration, Backup, Staging – WPvivid <= 0.9.55 - Reflected Cross-Site Scripting

medium

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 0.9.55 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...

CVSS:
6.1
Affected:
up to 0.9.55
Fixed in:
0.9.56
Disclosed:
Aug 9, 2021

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.56

unknown

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 0.9.55 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...

Affected:
up to 0.9.56
Fixed in:
0.9.56
Disclosed:
Aug 9, 2021

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.53

unknown

SQL Injection (SQLi) vulnerability discovered in WordPress WPvivid Backup and Migration plugin (versions <= 0.9.52).

Affected:
up to 0.9.53
Fixed in:
0.9.53
Disclosed:
Apr 26, 2021

Migration, Backup, Staging – WPvivid <= 0.9.35 - Sensitive Information Disclosure

medium

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a WordPress site's database due to missing capability checks on the wp_ajax_wpvivid_add_remote AJAX action that allows low-level authenticated attackers to send back-ups to a remote location of their choic...

CVSS:
4.9
Affected:
up to 0.9.36
Fixed in:
0.9.36
Disclosed:
Mar 23, 2020

CVE-2020-36835 on NVD →

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.36

unknown

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a WordPress site's database due to missing capability checks on the wp_ajax_wpvivid_add_remote AJAX action that allows low-level authenticated attackers to send back-ups to a remote location of their choic...

Affected:
up to 0.9.36
Fixed in:
0.9.36
Disclosed:
Mar 23, 2020

Migration, Backup, Staging – WPvivid <= 0.9.35 - Authenticated (Subscriber+) Arbitrary File Upload

high

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the wpvivid_upload_import_files and wpvivid_upload_files AJAX actions that allows low-level authenticated attackers to upload zip files that can be subsequently extracted. This affe...

CVSS:
8.8
Affected:
up to 0.9.35
Fixed in:
0.9.36
Disclosed:
Mar 13, 2020

CVE-2020-36842 on NVD →

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.36

unknown

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the wpvivid_upload_import_files and wpvivid_upload_files AJAX actions that allows low-level authenticated attackers to upload zip files that can be subsequently extracted. This affe...

Affected:
up to 0.9.36
Fixed in:
0.9.36
Disclosed:
Mar 13, 2020

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.36

unknown

Missing Authorization vulnerability leading to Database Leak discovered by Dave Jong (Patchstack) in WordPress WPvivid Backup and Migration plugin (versions <= 0.9.35).

Affected:
up to 0.9.36
Fixed in:
0.9.36
Disclosed:
Feb 28, 2020

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.56

unknown

The plugin does not escape the tab parameter before outputting it back in an admin dashboard page, leading to a Reflected Cross-Site Scripting issue

Affected:
up to 0.9.56
Fixed in:
0.9.56

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.117

unknown
Affected:
up to 0.9.117
Fixed in:
0.9.117

CVE-2025-5961 on NVD →

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.91

unknown

The Migration, Backup, Staging &ndash; WPvivid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the backup path parameter in versions up to, and including, 0.9.90 due to insufficient input sanitization and output escaping on the &#039;path&#039; setting. This makes it possible for authenticated att...

Affected:
up to 0.9.91
Fixed in:
0.9.91

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.77

unknown

The plugin introduced an issue in its delete_upload_incomplete_backup AJAX action, which could allow high privilege users to delete arbitrary file on the server via a path traversal attack

Affected:
up to 0.9.77
Fixed in:
0.9.77

Migration, Backup, Staging – WPvivid Backup &amp; Migration [wpvivid-backuprestore] < 0.9.36

unknown

There is a missing authorization check in the WPvivid Backup plugin that can lead to the exposure of the database and all files of the WordPress site. wp_ajax_wpvivid_add_remote does not check if the current user has the proper permission to execute the action to add a new remote backup location, nor does it (and ma...

Affected:
up to 0.9.36
Fixed in:
0.9.36

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database