Skip to main content

Vendor archive

wpvivid CVEs

Beta · best-effort

23 CVEs tagged to vendor wpvivid1 Critical, 11 High, 10 Medium, 1 Low, 0 Unrated.

CVE-2025-5961

Published Jul 3, 2025

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpvivid_upload…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-13869

Published Feb 22, 2025

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_files'…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-56273

Published Jan 7, 2025

Missing Authorization vulnerability in wpvividplugins WPvivid Backup and Migration wpvivid-backuprestore allows Accessing Functionality Not Properly Constrained by ACLs.This issue…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10962

Published Nov 14, 2024

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.9.107 via deserialization of untrusted…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36842

Published Oct 16, 2024

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the wpvivid_upload_import_files and wpvi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36835

Published Oct 16, 2024

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a WordPress site's database due to missing capability checks on…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7315

Published Oct 2, 2024

The Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient randomness in the filename that is created when generating a backup, which could be brutefo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-35664

Published Jun 4, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpvividplugins WPvivid Backup for MainWP wpvivid-backup-mainwp allows Reflect…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-41243

Published May 17, 2024

Improper Privilege Management vulnerability in WPvivid Team WPvivid Backup and Migration allows Privilege Escalation.This issue affects WPvivid Backup and Migration: from n/a thro…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-3054

Published Apr 12, 2024

WPvivid Backup & Migration Plugin for WordPress is vulnerable to PHAR Deserialization in all versions up to, and including, 0.9.99 via deserialization of untrusted input at the wp…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1383

Published Mar 13, 2024

The WPvivid Backup for MainWP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in all versions up to, and including, 0.9.32 due to insuf…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1982

Published Feb 29, 2024

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the get_restore_progress() and restore() fu…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1981

Published Feb 29, 2024

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to SQL Injection via the 'table_prefix' parameter in version 0.9.68 due to insufficient escaping on the…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-4637

Published Feb 5, 2024

The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the restore() and get_restore_progress() function in versions up…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-5121

Published Oct 20, 2023

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings (the backup path parameter) in versions up to, and in…

CVSS 4.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-5576

Published Oct 20, 2023

The Migration, Backup, Staging - WPvivid plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 0.9.91 via Google Drive API secrets…

CVSS 8.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-5120

Published Oct 20, 2023

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image file path parameter in versions up to, and including, 0.9.…

CVSS 4.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-4274

Published Oct 20, 2023

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 0.9.89. This allows authenticated attackers wi…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-2863

Published Sep 16, 2022

The Migration, Backup, Staging WordPress plugin before 0.9.76 does not sanitise and validate a parameter before using it to read the content of a file, allowing high privilege use…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2442

Published Sep 6, 2022

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to deserialization of untrusted input via the 'path' parameter in versions up to, and including 0.9.7…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-0531

Published Apr 11, 2022

The Migration, Backup, Staging WordPress plugin before 0.9.70 does not sanitise and escape the sub_page parameter before outputting it back in the page, leading to a reflected Cro…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24994

Published Feb 28, 2022

The Migration, Backup, Staging WordPress plugin before 0.9.69 does not have authorisation when adding remote storages, and does not sanitise as well as escape a parameter from suc…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-23 of 23 CVEsPage 1 of 1