PatchSiren

wpvividplugins CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM wpvividplugins CVE published 2026-08-01

CVE-2026-17555

The WPvivid Backup & Migration plugin for WordPress, specifically versions up to and including 0.9.131, is vulnerable to SQL Injection via the export_data parameter. This vulnerability is due to insufficient escaping on the user-supplied parameter and a lack of sufficient preparation on the existing SQL query. The vulnerability allows authenticated attackers with Administrator-level access and above to ap [truncated]

MEDIUM wpvividplugins CVE published 2026-07-10

CVE-2026-15283

The WPvivid Backup for MainWP plugin for WordPress has a Stored Cross-Site Scripting vulnerability due to insufficient input sanitization and output escaping in admin settings. Authenticated attackers with administrator-level permissions can inject web scripts, affecting multi-site installations and those with unfiltered_html disabled. This vulnerability has a CVSS score of 4.4, indicating a Medium severi [truncated]

LOW wpvividplugins CVE published 2026-06-06

CVE-2025-12656

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in the delete_cancel_staging_site() function in all versions up to, and including, 0.9.128. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary folders on the server, which lead [truncated]