VYPR

WPvivid

by WordPress

CVEs (5)

  • CVE-2020-36842HigOct 16, 2024
    risk 0.57cvss 8.8epss 0.01

    The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the wpvivid_upload_import_files and wpvivid_upload_files AJAX actions that allows low-level authenticated attackers to upload zip files…

  • CVE-2026-19722MedAug 30, 2026
    risk 0.43cvss 6.6epss 0.00

    The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, allowing high privilege users such as administrators to write arbitrary files outside the intended restore…

  • CVE-2026-82194MedSep 4, 2026
    risk 0.36cvss 5.5epss 0.00

    The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before using it in a file deletion routine, allowing administrators to delete arbitrary files on the server, including files outside the web root.

  • CVE-2026-82193MedSep 4, 2026
    risk 0.36cvss 5.5epss 0.00

    The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied file name before using it to build a write path, allowing administrators to write files of permitted types to arbitrary locations on the server and to overwrite existing…

  • CVE-2026-82182MedSep 2, 2026
    risk 0.27cvss 4.1epss 0.00

    The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not sanitise a user supplied list of identifiers before using it in a SQL query, allowing administrators to perform SQL injection attacks.