WPvivid — Backup, Migration & Staging < 0.9.131 - Unauthenticated Path Traversal
high
The WPvivid — Backup, Migration & Staging plugin for WordPress is vulnerable to Path Traversal in all versions up to 0.9.131. This is due to insufficient validation of a user supplied path. This makes it possible for unauthenticated attackers to access files and directories outside of the intended directory.
- CVSS:
- 7.5
- Affected:
- up to 0.9.131
- Fixed in:
- 0.9.131
- Disclosed:
- Aug 20, 2026
CVE-2026-19725 on NVD →
WPvivid <= 0.9.131 - Authenticated (Administrator+) SQL Injection via 'export_data' Parameter
medium
The WPvivid Backup & Migration plugin for WordPress is vulnerable to SQL Injection via the export_data parameter in versions up to, and including, 0.9.131. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. The values are received in prepare...
- CVSS:
- 4.9
- Affected:
- up to 0.9.131
- Fixed in:
- 0.9.132
- Disclosed:
- Jul 31, 2026
CVE-2026-17555 on NVD →
Migration, Backup, Staging – WPvivid Backup & Migration <= 0.9.128 - Authenticated (Admin+) Arbitrary Directory Deletion
low
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in the delete_cancel_staging_site() function in all versions up to, and including, 0.9.128. This makes it possible for authenticated attackers, with Adm...
- CVSS:
- 3.8
- Affected:
- up to 0.9.128
- Fixed in:
- 0.9.129
- Disclosed:
- Jun 5, 2026
CVE-2025-12656 on NVD →
Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload
critical
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions up to and including 0.9.123. This is due to improper error handling in the RSA decryption process combined with a lack of path sanitization when writing uploaded files. Whe...
- CVSS:
- 9.8
- Affected:
- up to 0.9.123
- Fixed in:
- 0.9.124
- Disclosed:
- Feb 10, 2026
CVE-2026-1357 on NVD →
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] <= 0.9.120 (unfixed)
unknown
[en] The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory creation in all versions up to, and including, 0.9.120. This is due to the check_filesystem_permissions() function not properly restricting the directories that can be created, or in what location....
- Affected:
- up to 0.9.120
- Fix:
- No patched version reported
- Disclosed:
- Dec 21, 2025
CVE-2025-12654 on NVD →
Migration, Backup, Staging – WPvivid Backup & Migration <= 0.9.120 - Authenticated (Admin+) Arbitrary Directory Creation
low
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory creation in all versions up to, and including, 0.9.120. This is due to the check_filesystem_permissions() function not properly restricting the directories that can be created, or in what location. This...
- CVSS:
- 2.7
- Affected:
- up to 0.9.120
- Fixed in:
- 0.9.121
- Disclosed:
- Dec 20, 2025
CVE-2025-12654 on NVD →
Migration, Backup, Staging – WPvivid Backup & Migration <= 0.9.116 - Authenticated (Administrator+) Arbitrary File Upload
high
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpvivid_upload_import_files' function in all versions up to, and including, 0.9.116. This makes it possible for authenticated attackers, with Administrator...
- CVSS:
- 7.2
- Affected:
- up to 0.9.116
- Fixed in:
- 0.9.117
- Disclosed:
- Jul 3, 2025
CVE-2025-5961 on NVD →
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.113
unknown
[en] The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_files' function in all versions up to, and including, 0.9.112. This makes it possible for authenticated attackers, with Administrator-level acc...
- Affected:
- up to 0.9.113
- Fixed in:
- 0.9.113
- Disclosed:
- Feb 22, 2025
CVE-2024-13869 on NVD →
Migration, Backup, Staging – WPvivid <= 0.9.112 - Authenticated (Admin+) Arbitrary File Upload via wpvivid_upload_file
high
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_files' function in all versions up to, and including, 0.9.112. This makes it possible for authenticated attackers, with Administrator-level access a...
- CVSS:
- 7.2
- Affected:
- up to 0.9.112
- Fixed in:
- 0.9.113
- Disclosed:
- Feb 21, 2025
CVE-2024-13869 on NVD →
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.107
unknown
[en] Missing Authorization vulnerability in WPvivid Backup & Migration WPvivid Backup and Migration allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPvivid Backup and Migration: from n/a through 0.9.106.
- Affected:
- up to 0.9.107
- Fixed in:
- 0.9.107
- Disclosed:
- Jan 7, 2025
CVE-2024-56273 on NVD →
WPvivid Backup and Migration <= 0.9.106 - Missing Authorization
medium
The WPvivid Backup and Migration plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the handle_auth_actions() function in versions up to, and including, 0.9.106. This makes it possible for unauthenticated attackers to connect their dropbox account.
- CVSS:
- 5.3
- Affected:
- up to 0.9.106
- Fixed in:
- 0.9.107
- Disclosed:
- Jan 3, 2025
CVE-2024-56273 on NVD →
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.108
unknown
[en] The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.9.107 via deserialization of untrusted input in the 'replace_row_data' and 'replace_serialize_data' functions. This makes it possible for unauthenticated attackers to inject a...
- Affected:
- up to 0.9.108
- Fixed in:
- 0.9.108
- Disclosed:
- Nov 14, 2024
CVE-2024-10962 on NVD →
Migration, Backup, Staging – WPvivid <= 0.9.107 - Unauthenticated PHP Object Injection
high
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.9.107 via deserialization of untrusted input in the 'replace_row_data' and 'replace_serialize_data' functions. This makes it possible for unauthenticated attackers to inject a PHP...
- CVSS:
- 8.8
- Affected:
- up to 0.9.107
- Fixed in:
- 0.9.108
- Disclosed:
- Nov 13, 2024
CVE-2024-10962 on NVD →
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.36
unknown
[en] The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a WordPress site's database due to missing capability checks on the wp_ajax_wpvivid_add_remote AJAX action that allows low-level authenticated attackers to send back-ups to a remote location of their...
- Affected:
- up to 0.9.36
- Fixed in:
- 0.9.36
- Disclosed:
- Oct 16, 2024
CVE-2020-36835 on NVD →
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.36
unknown
[en] The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the wpvivid_upload_import_files and wpvivid_upload_files AJAX actions that allows low-level authenticated attackers to upload zip files that can be subsequently extracted. This...
- Affected:
- up to 0.9.36
- Fixed in:
- 0.9.36
- Disclosed:
- Oct 16, 2024
CVE-2020-36842 on NVD →
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.106
unknown
[en] The Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient randomness in the filename that is created when generating a backup, which could be bruteforced by attackers to leak sensitive information about said backups.
- Affected:
- up to 0.9.106
- Fixed in:
- 0.9.106
- Disclosed:
- Oct 2, 2024
CVE-2024-7315 on NVD →
Migration, Backup, Staging – WPvivid <= 0.9.105 - Sensitive Information Exposure
high
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 0.9.105. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data by brute-forcing backup file names.
- CVSS:
- 7.5
- Affected:
- up to 0.9.105
- Fixed in:
- 0.9.106
- Disclosed:
- Sep 11, 2024
CVE-2024-7315 on NVD →
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.91
unknown
[en] Improper Privilege Management vulnerability in WPvivid Team WPvivid Backup and Migration allows Privilege Escalation.This issue affects WPvivid Backup and Migration: from n/a through 0.9.90.
- Affected:
- up to 0.9.91
- Fixed in:
- 0.9.91
- Disclosed:
- May 17, 2024
CVE-2023-41243 on NVD →
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.100
unknown
[en] WPvivid Backup & Migration Plugin for WordPress is vulnerable to PHAR Deserialization in all versions up to, and including, 0.9.99 via deserialization of untrusted input at the wpvividstg_get_custom_exclude_path_free action. This is due to the plugin not providing sufficient path validation on the tree_node[node][...
- Affected:
- up to 0.9.100
- Fixed in:
- 0.9.100
- Disclosed:
- Apr 12, 2024
CVE-2024-3054 on NVD →
WPvivid Backup & Migration Plugin <= 0.9.99 - Authenticated (Admin+) PHAR Deserialization
high
WPvivid Backup & Migration Plugin for WordPress is vulnerable to PHAR Deserialization in all versions up to, and including, 0.9.99 via deserialization of untrusted input at the wpvividstg_get_custom_exclude_path_free action. This is due to the plugin not providing sufficient path validation on the tree_node[node][id] p...
- CVSS:
- 7.2
- Affected:
- up to 0.9.99
- Fixed in:
- 0.9.100
- Disclosed:
- Apr 11, 2024
CVE-2024-3054 on NVD →
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.69
unknown
[en] The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the get_restore_progress() and restore() functions in all versions up to, and including, 0.9.68. This makes it possible for unauthenticated attackers to exploit a SQL injection vu...
- Affected:
- up to 0.9.69
- Fixed in:
- 0.9.69
- Disclosed:
- Feb 29, 2024
CVE-2024-1982 on NVD →
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.69
unknown
[en] The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to SQL Injection via the 'table_prefix' parameter in version 0.9.68 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attac...
- Affected:
- up to 0.9.69
- Fixed in:
- 0.9.69
- Disclosed:
- Feb 29, 2024
CVE-2024-1981 on NVD →
WPvivid Backup and Migration <= 0.9.68 - Unauthenticated SQL Injection
critical
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to SQL Injection via the 'table_prefix' parameter in version 0.9.68 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers...
- CVSS:
- 9.8
- Affected:
- 0.9.68 – 0.9.68
- Fixed in:
- 0.9.69
- Disclosed:
- Feb 28, 2024
CVE-2024-1981 on NVD →
WPvivid Backup and Migration <= 0.9.68 - Missing Authorization
medium
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the get_restore_progress() and restore() functions in all versions up to, and including, 0.9.68. This makes it possible for unauthenticated attackers to exploit a SQL injection vulnera...
- CVSS:
- 6.5
- Affected:
- up to 0.9.68
- Fixed in:
- 0.9.69
- Disclosed:
- Feb 28, 2024
CVE-2024-1982 on NVD →
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.95
unknown
[en] The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the restore() and get_restore_progress() function in versions up to, and including, 0.9.94. This makes it possible for unauthenticated attackers to invoke these functions and obtain full file paths if...
- Affected:
- up to 0.9.95
- Fixed in:
- 0.9.95
- Disclosed:
- Feb 5, 2024
CVE-2023-4637 on NVD →
WPvivid <= 0.9.94 - Missing Authorization
medium
The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the restore() and get_restore_progress() function in versions up to, and including, 0.9.94. This makes it possible for unauthenticated attackers to invoke these functions and obtain full file paths if they...
- CVSS:
- 4.3
- Affected:
- up to 0.9.94
- Fixed in:
- 0.9.95
- Disclosed:
- Jan 19, 2024
CVE-2023-4637 on NVD →
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.90
unknown
[en] The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings (the backup path parameter) in versions up to, and including, 0.9.89 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with adm...
- Affected:
- up to 0.9.90
- Fixed in:
- 0.9.90
- Disclosed:
- Oct 20, 2023
CVE-2023-5121 on NVD →
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.92
unknown
[en] The Migration, Backup, Staging - WPvivid plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 0.9.91 via Google Drive API secrets stored in plaintext in the publicly visible plugin source. This could allow unauthenticated attackers to impersonate the WPVivid Google...
- Affected:
- up to 0.9.92
- Fixed in:
- 0.9.92
- Disclosed:
- Oct 20, 2023
CVE-2023-5576 on NVD →
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.90
unknown
[en] The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image file path parameter in versions up to, and including, 0.9.89 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative pr...
- Affected:
- up to 0.9.90
- Fixed in:
- 0.9.90
- Disclosed:
- Oct 20, 2023
CVE-2023-5120 on NVD →
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.90
unknown
[en] The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 0.9.89. This allows authenticated attackers with administrative privileges to delete the contents of arbitrary directories on the server, which can be a critical issue in a shared en...
- Affected:
- up to 0.9.90
- Fixed in:
- 0.9.90
- Disclosed:
- Oct 20, 2023
CVE-2023-4274 on NVD →
Migration, Backup, Staging – WPvivid <= 0.9.91 - Google Drive Client Secret Exposure
high
The Migration, Backup, Staging - WPvivid plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 0.9.91 via Google Drive API secrets stored in plaintext in the publicly visible plugin source. This could allow unauthenticated attackers to impersonate the WPVivid Google Driv...
- CVSS:
- 8
- Affected:
- up to 0.9.91
- Fixed in:
- 0.9.92
- Disclosed:
- Oct 13, 2023
CVE-2023-5576 on NVD →
Migration, Backup, Staging – WPvivid <= 0.9.89 - Authenticated (Administrator+) Arbitrary Directory Deletion via Path Traversal
high
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 0.9.89. This allows authenticated attackers with administrative privileges to delete the contents of arbitrary directories on the server, which can be a critical issue in a shared environ...
- CVSS:
- 8.7
- Affected:
- 0.9.89 – 0.9.89
- Fixed in:
- 0.9.90
- Disclosed:
- Sep 22, 2023
CVE-2023-4274 on NVD →
Migration, Backup, Staging – WPvivid <= 0.9.89 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings (the backup path parameter) in versions up to, and including, 0.9.89 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administ...
- CVSS:
- 4.4
- Affected:
- up to 0.9.89
- Fixed in:
- 0.9.90
- Disclosed:
- Sep 22, 2023
CVE-2023-5121 on NVD →
Migration, Backup, Staging – WPvivid <= 0.9.89 - Authenticated Stored Cross-Site Scripting
medium
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image file path parameter in versions up to, and including, 0.9.89 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privile...
- CVSS:
- 4.4
- Affected:
- up to 0.9.89
- Fixed in:
- 0.9.90
- Disclosed:
- Sep 22, 2023
CVE-2023-5120 on NVD →
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.91
unknown
Update the WordPress WPvivid Backup and Migration plugin to the latest available version (at least 0.9.91).
Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress WPvivid Backup and Migration Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, a...
- Affected:
- up to 0.9.91
- Fixed in:
- 0.9.91
- Disclosed:
- Sep 13, 2023
WPvivid Backup Plugin <= 0.9.90 - Missing Authorization via 'start_staging' and 'get_staging_progress'
high
The WPvivid Backup Plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the 'start_staging' and 'get_staging_progress' functions in versions up to, and including, 0.9.90. This makes it possible for authenticated attackers to create new staging s...
- CVSS:
- 8.3
- Affected:
- up to 0.9.91
- Fixed in:
- 0.9.91
- Disclosed:
- Sep 12, 2023
CVE-2023-41243 on NVD →
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.91
unknown
The WPvivid Backup Plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the 'start_staging' and 'get_staging_progress' functions in versions up to, and including, 0.9.90. This makes it possible for authenticated attackers to create new staging s...
- Affected:
- up to 0.9.91
- Fixed in:
- 0.9.91
- Disclosed:
- Sep 12, 2023
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.76
unknown
[en] The Migration, Backup, Staging WordPress plugin before 0.9.76 does not sanitise and validate a parameter before using it to read the content of a file, allowing high privilege users to read any file from the web server via a Traversal attack
- Affected:
- up to 0.9.76
- Fixed in:
- 0.9.76
- Disclosed:
- Sep 16, 2022
CVE-2022-2863 on NVD →
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.76
unknown
[en] The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to deserialization of untrusted input via the 'path' parameter in versions up to, and including 0.9.74. This makes it possible for authenticated attackers with administrative privileges to call files using a PHAR wrapper that will deseri...
- Affected:
- up to 0.9.76
- Fixed in:
- 0.9.76
- Disclosed:
- Sep 6, 2022
CVE-2022-2442 on NVD →
WPvivid Backup 0.9.76 - Authenticated (Administrator+) Arbitrary File Deletion
medium
The WPvivid Backup plugin for WordPress is vulnerable to Path Traversal in version 0.9.76 due to a newly introduced delete_upload_incomplete_backup AJAX action. This allows administrator-level attackers to delete arbitrary files on the server.
- CVSS:
- 6.5
- Affected:
- 0.9.76 – 0.9.76
- Fixed in:
- 0.9.77
- Disclosed:
- Aug 29, 2022
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.77
unknown
Authenticated Arbitrary File Deletion vulnerability discovered by WPScan in WordPress WPvivid Backup plugin (versions 0.9.76).
Update the WordPress WPvivid Backup and Migration plugin to the latest available version (at least 0.9.77).
- Affected:
- up to 0.9.77
- Fixed in:
- 0.9.77
- Disclosed:
- Aug 29, 2022
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.77
unknown
The WPvivid Backup plugin for WordPress is vulnerable to Path Traversal in version 0.9.76 due to a newly introduced delete_upload_incomplete_backup AJAX action. This allows administrator-level attackers to delete arbitrary files on the server.
- Affected:
- up to 0.9.77
- Fixed in:
- 0.9.77
- Disclosed:
- Aug 29, 2022
Migration, Backup, Staging – WPvivid <= 0.9.75 - Authenticated (Administrator+) Path Traversal
medium
The WPvivid backup plugin for WordPress is vulnerable to arbitrary file read due to missing parameter sanitization and validation on the 'file_name' parameter in versions up to, and including, 0.9.75. This makes it possible for authenticated attackers, with administrator level permissions and above, to access arbitrar...
- CVSS:
- 6.5
- Affected:
- up to 0.9.75
- Fixed in:
- 0.9.76
- Disclosed:
- Aug 22, 2022
CVE-2022-2863 on NVD →
Migration, Backup, Staging – WPvivid <= 0.9.75 - Authenticated (Admin+) Directory Traversal
medium
The WPvivid plugin for WordPress is vulnerable to directory traversal in versions up to, and including, 0.9.75. This allows authenticated users with administrative privileges to download arbitrary files on the server, including sensitive configuration files, though the file size must be successfully guessed in order to...
- CVSS:
- 6
- Affected:
- up to 0.9.75
- Fixed in:
- 0.9.76
- Disclosed:
- Aug 16, 2022
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.76
unknown
The WPvivid plugin for WordPress is vulnerable to directory traversal in versions up to, and including, 0.9.75. This allows authenticated users with administrative privileges to download arbitrary files on the server, including sensitive configuration files, though the file size must be successfully guessed in order to...
- Affected:
- up to 0.9.76
- Fixed in:
- 0.9.76
- Disclosed:
- Aug 16, 2022
Migration, Backup, Staging – WPvivid <= 0.9.74 - Authenticated (Admin+) PHAR Deserialization
high
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to deserialization of untrusted input via the 'path' parameter in versions up to, and including 0.9.74. This makes it possible for authenticated attackers with administrative privileges to call files using a PHAR wrapper that will deserialize...
- CVSS:
- 7.2
- Affected:
- up to 0.9.74
- Fixed in:
- 0.9.75
- Disclosed:
- Aug 10, 2022
CVE-2022-2442 on NVD →
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.70
unknown
[en] The Migration, Backup, Staging WordPress plugin before 0.9.70 does not sanitise and escape the sub_page parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting
- Affected:
- up to 0.9.70
- Fixed in:
- 0.9.70
- Disclosed:
- Apr 11, 2022
CVE-2022-0531 on NVD →
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.71
unknown
[en] Arbitrary File Read vulnerability in WPvivid Team Migration, Backup, Staging – WPvivid (WordPress plugin) versions <= 0.9.70
- Affected:
- up to 0.9.71
- Fixed in:
- 0.9.71
- Disclosed:
- Apr 11, 2022
CVE-2022-27844 on NVD →
Migration, Backup, Staging – WPvivid <= 0.9.70 - Authenticated Arbitrary File Read
medium
Arbitrary File Read vulnerability in WPvivid Team Migration, Backup, Staging – WPvivid (WordPress plugin) versions <= 0.9.70
- CVSS:
- 4.9
- Affected:
- up to 0.9.70
- Fixed in:
- 0.9.71
- Disclosed:
- Apr 7, 2022
CVE-2022-27844 on NVD →
Migration, Backup, Staging – WPvivid <= 0.9.69 - Reflected Cross-Site Scripting via sub_page Parameter
medium
The Migration, Backup, Staging WordPress plugin before 0.9.70 does not sanitise and escape the sub_page parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
- CVSS:
- 6.1
- Affected:
- up to 0.9.70
- Fixed in:
- 0.9.70
- Disclosed:
- Mar 21, 2022
CVE-2022-0531 on NVD →
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.71
unknown
[en] The Migration, Backup, Staging WordPress plugin before 0.9.69 does not have authorisation when adding remote storages, and does not sanitise as well as escape a parameter from such unauthenticated requests before outputting it in admin page, leading to a Stored Cross-Site Scripting issue
- Affected:
- up to 0.9.71
- Fixed in:
- 0.9.71
- Disclosed:
- Feb 28, 2022
CVE-2021-24994 on NVD →
Migration, Backup, Staging – WPvivid <= 0.9.68 - Unauthenticated Stored Cross-Site Scripting
medium
The Migration, Backup, Staging – WPvivid plugin before 0.9.69 does not have authorisation when adding remote storages, and does not sanitise as well as escape a parameter from such unauthenticated requests before outputting it in admin page, leading to a Stored Cross-Site Scripting issue
- CVSS:
- 6.1
- Affected:
- up to 0.9.69
- Fixed in:
- 0.9.69
- Disclosed:
- Jan 31, 2022
CVE-2021-24994 on NVD →
Migration, Backup, Staging – WPvivid <= 0.9.55 - Reflected Cross-Site Scripting
medium
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 0.9.55 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...
- CVSS:
- 6.1
- Affected:
- up to 0.9.55
- Fixed in:
- 0.9.56
- Disclosed:
- Aug 9, 2021
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.56
unknown
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 0.9.55 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...
- Affected:
- up to 0.9.56
- Fixed in:
- 0.9.56
- Disclosed:
- Aug 9, 2021
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.53
unknown
SQL Injection (SQLi) vulnerability discovered in WordPress WPvivid Backup and Migration plugin (versions <= 0.9.52).
- Affected:
- up to 0.9.53
- Fixed in:
- 0.9.53
- Disclosed:
- Apr 26, 2021
Migration, Backup, Staging – WPvivid <= 0.9.35 - Sensitive Information Disclosure
medium
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a WordPress site's database due to missing capability checks on the wp_ajax_wpvivid_add_remote AJAX action that allows low-level authenticated attackers to send back-ups to a remote location of their choic...
- CVSS:
- 4.9
- Affected:
- up to 0.9.36
- Fixed in:
- 0.9.36
- Disclosed:
- Mar 23, 2020
CVE-2020-36835 on NVD →
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.36
unknown
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a WordPress site's database due to missing capability checks on the wp_ajax_wpvivid_add_remote AJAX action that allows low-level authenticated attackers to send back-ups to a remote location of their choic...
- Affected:
- up to 0.9.36
- Fixed in:
- 0.9.36
- Disclosed:
- Mar 23, 2020
Migration, Backup, Staging – WPvivid <= 0.9.35 - Authenticated (Subscriber+) Arbitrary File Upload
high
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the wpvivid_upload_import_files and wpvivid_upload_files AJAX actions that allows low-level authenticated attackers to upload zip files that can be subsequently extracted. This affe...
- CVSS:
- 8.8
- Affected:
- up to 0.9.35
- Fixed in:
- 0.9.36
- Disclosed:
- Mar 13, 2020
CVE-2020-36842 on NVD →
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.36
unknown
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the wpvivid_upload_import_files and wpvivid_upload_files AJAX actions that allows low-level authenticated attackers to upload zip files that can be subsequently extracted. This affe...
- Affected:
- up to 0.9.36
- Fixed in:
- 0.9.36
- Disclosed:
- Mar 13, 2020
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.36
unknown
Missing Authorization vulnerability leading to Database Leak discovered by Dave Jong (Patchstack) in WordPress WPvivid Backup and Migration plugin (versions <= 0.9.35).
- Affected:
- up to 0.9.36
- Fixed in:
- 0.9.36
- Disclosed:
- Feb 28, 2020
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.56
unknown
The plugin does not escape the tab parameter before outputting it back in an admin dashboard page, leading to a Reflected Cross-Site Scripting issue
- Affected:
- up to 0.9.56
- Fixed in:
- 0.9.56
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.117
unknown
- Affected:
- up to 0.9.117
- Fixed in:
- 0.9.117
CVE-2025-5961 on NVD →
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.91
unknown
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the backup path parameter in versions up to, and including, 0.9.90 due to insufficient input sanitization and output escaping on the 'path' setting. This makes it possible for authenticated att...
- Affected:
- up to 0.9.91
- Fixed in:
- 0.9.91
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.77
unknown
The plugin introduced an issue in its delete_upload_incomplete_backup AJAX action, which could allow high privilege users to delete arbitrary file on the server via a path traversal attack
- Affected:
- up to 0.9.77
- Fixed in:
- 0.9.77
Migration, Backup, Staging – WPvivid Backup & Migration [wpvivid-backuprestore] < 0.9.36
unknown
There is a missing authorization check in the WPvivid Backup plugin that can lead to the exposure of the database and all files of the WordPress site.
wp_ajax_wpvivid_add_remote does not check if the current user has the proper permission to execute the action to add a new remote backup location, nor does it (and ma...
- Affected:
- up to 0.9.36
- Fixed in:
- 0.9.36