VYPR

WPvivid Backup & Migration

by WordPress

CVEs (5)

  • CVE-2026-1357CriFeb 11, 2026
    risk 0.58cvss 9.8epss 0.16

    The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions up to and including 0.9.123. This is due to improper error handling in the RSA decryption process combined with a lack of path…

  • CVE-2024-1982MedFeb 29, 2024
    risk 0.42cvss 6.5epss 0.00

    The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the get_restore_progress() and restore() functions in all versions up to, and including, 0.9.68. This makes it possible for unauthenticated…

  • CVE-2025-12656LowJun 6, 2026
    risk 0.25cvss 3.8epss

    The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in the delete_cancel_staging_site() function in all versions up to, and including, 0.9.128. This makes it…

  • CVE-2025-5961Jul 3, 2025
    risk 0.00cvss epss 0.02

    The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpvivid_upload_import_files' function in all versions up to, and including, 0.9.116. This makes it possible for…

  • CVE-2024-13869Feb 22, 2025
    risk 0.00cvss epss 0.22

    The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_files' function in all versions up to, and including, 0.9.112. This makes it possible for authenticated…