Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload
WPvivid — Backup, Migration & Staging
Minimum safe version
0.9.124
Update to 0.9.124 or later to address 37 fixable vulnerabilities
CVE-2025-12654
Migration, Backup, Staging – WPvivid Backup & Migration <= 0.9.116 - Authenticated (Administrator+) Arbitrary File Upload
CVE-2024-13869
CVE-2024-56273
CVE-2024-10962
CVE-2020-36842
CVE-2020-36835
CVE-2024-7315
WordPress WPvivid Backup and Migration Plugin <= 0.9.99 is vulnerable to PHP Object Injection
CVE-2024-1981
CVE-2024-1982
CVE-2023-4637
CVE-2023-5576
CVE-2023-5120
CVE-2023-4274
CVE-2023-5121
WordPress WPvivid Backup and Migration Plugin <= 0.9.90 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-41243
Migration, Backup, Staging – WPvivid <= 0.9.90 - Authenticated(Administrator+) Stored Cross-Site Scripting
WPvivid Backup Plugin <= 0.9.90 - Missing Authorization via 'start_staging' and 'get_staging_progress'
WPvivid Backup < 0.9.36 - Missing Authorization Leading To Database Leak
WPvivid Backup 0.9.76 - Admin+ Arbitrary File Deletion
WPvivid Backup < 0.9.56 - Reflected Cross-Site Scripting
Migration, Backup, Staging – WPvivid <= 0.9.35 - Authenticated (Subscriber+) Arbitrary File Upload
Migration, Backup, Staging – WPvivid <= 0.9.35 - Sensitive Information Disclosure
Migration, Backup, Staging – WPvivid <= 0.9.55 - Reflected Cross-Site Scripting
Migration, Backup, Staging – WPvivid <= 0.9.75 - Authenticated (Admin+) Directory Traversal
WPvivid Backup 0.9.76 - Authenticated (Administrator+) Arbitrary File Deletion
CVE-2022-2863
WordPress WPvivid Backup plugin 0.9.76 - Authenticated Arbitrary File Deletion vulnerability
CVE-2022-2442
WordPress WPvivid Backup and Migration plugin <= 0.9.35 - Missing Authorization vulnerability leading to Database Leak
WordPress WPvivid Backup and Migration plugin <= 0.9.52 - SQL Injection (SQLi) vulnerability
CVE-2022-27844
CVE-2022-0531
CVE-2021-24994