Extension WordPress
Vulnérabilités WPvivid , Backup, Migration & Staging
Cette page rassemble les failles publiées pour WPvivid , Backup, Migration & Staging, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WPvivid , Backup, Migration & Staging
27 fiches
Migration, Backup, Staging – WPvivid Backup & Migration <= 0.9.128 – Authenticated (Admin+) Arbitrary Directory Deletion
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in the delete_cancel_staging_site() function in all versions up to, and including, 0.9.128. This makes…
*-0.9.128
0.9.129
05/06/2026
Migration, Backup, Staging <= 0.9.123 – Unauthenticated Arbitrary File Upload
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions up to and including 0.9.123. This is due to improper error handling in the RSA decryption process…
*-0.9.123
0.9.124
10/02/2026
Migration, Backup, Staging – WPvivid Backup & Migration <= 0.9.120 – Authenticated (Admin+) Arbitrary Directory Creation
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory creation in all versions up to, and including, 0.9.120. This is due to the check_filesystem_permissions() function not properly restricting the directories…
*-0.9.120
0.9.121
20/12/2025
Migration, Backup, Staging – WPvivid Backup & Migration <= 0.9.116 – Authenticated (Administrator+) Arbitrary File Upload
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpvivid_upload_import_files' function in all versions up to, and including, 0.9.116. This makes…
*-0.9.116
0.9.117
03/07/2025
Migration, Backup, Staging – WPvivid <= 0.9.112 – Authenticated (Admin+) Arbitrary File Upload via wpvivid_upload_file
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_files' function in all versions up to, and including, 0.9.112. This makes…
*-0.9.112
0.9.113
21/02/2025
WPvivid Backup and Migration <= 0.9.106 – Missing Authorization
The WPvivid Backup and Migration plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the handle_auth_actions() function in versions up to, and including, 0.9.106. This makes it possible for unauthenticated attackers to…
*-0.9.106
0.9.107
03/01/2025
Migration, Backup, Staging – WPvivid <= 0.9.107 – Unauthenticated PHP Object Injection
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.9.107 via deserialization of untrusted input in the 'replace_row_data' and 'replace_serialize_data' functions. This makes it possible…
*-0.9.107
0.9.108
13/11/2024
Migration, Backup, Staging – WPvivid <= 0.9.105 – Sensitive Information Exposure
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 0.9.105. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data by…
*-0.9.105
0.9.106
11/09/2024
WPvivid Backup & Migration Plugin <= 0.9.99 – Authenticated (Admin+) PHAR Deserialization
WPvivid Backup & Migration Plugin for WordPress is vulnerable to PHAR Deserialization in all versions up to, and including, 0.9.99 via deserialization of untrusted input at the wpvividstg_get_custom_exclude_path_free action. This is due to the plugin not providing sufficient…
*-0.9.99
0.9.100
11/04/2024
WPvivid Backup and Migration <= 0.9.68 – Unauthenticated SQL Injection
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to SQL Injection via the 'table_prefix' parameter in version 0.9.68 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…
0.9.68
0.9.69
28/02/2024
WPvivid Backup and Migration <= 0.9.68 – Missing Authorization
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the get_restore_progress() and restore() functions in all versions up to, and including, 0.9.68. This makes it possible…
*-0.9.68
0.9.69
28/02/2024
WPvivid <= 0.9.94 – Missing Authorization
The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the restore() and get_restore_progress() function in versions up to, and including, 0.9.94. This makes it possible for unauthenticated attackers…
*-0.9.94
0.9.95
19/01/2024
Migration, Backup, Staging – WPvivid <= 0.9.91 – Google Drive Client Secret Exposure
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 0.9.91 via Google Drive API secrets stored in plaintext in the publicly visible plugin source. This could…
*-0.9.91
0.9.92
13/10/2023
Migration, Backup, Staging – WPvivid <= 0.9.89 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings (the backup path parameter) in versions up to, and including, 0.9.89 due to insufficient input sanitization and output escaping. This…
*-0.9.89
0.9.90
22/09/2023
Migration, Backup, Staging – WPvivid <= 0.9.89 – Authenticated (Administrator+) Arbitrary Directory Deletion via Path Traversal
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 0.9.89. This allows authenticated attackers with administrative privileges to delete the contents of arbitrary directories on the server,…
0.9.89
0.9.90
22/09/2023
Migration, Backup, Staging – WPvivid <= 0.9.89 – Authenticated Stored Cross-Site Scripting
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image file path parameter in versions up to, and including, 0.9.89 due to insufficient input sanitization and output escaping. This makes…
*-0.9.89
0.9.90
22/09/2023
WPvivid Backup Plugin <= 0.9.90 – Missing Authorization via 'start_staging' and 'get_staging_progress'
The WPvivid Backup Plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the 'start_staging' and 'get_staging_progress' functions in versions up to, and including, 0.9.90. This makes…
[*, 0.9.91)
0.9.91
12/09/2023
WPvivid Backup 0.9.76 – Authenticated (Administrator+) Arbitrary File Deletion
The WPvivid Backup plugin for WordPress is vulnerable to Path Traversal in version 0.9.76 due to a newly introduced delete_upload_incomplete_backup AJAX action. This allows administrator-level attackers to delete arbitrary files on the server.
0.9.76
0.9.77
29/08/2022
Migration, Backup, Staging – WPvivid <= 0.9.75 – Authenticated (Administrator+) Path Traversal
The WPvivid backup plugin for WordPress is vulnerable to arbitrary file read due to missing parameter sanitization and validation on the 'file_name' parameter in versions up to, and including, 0.9.75. This makes it possible for authenticated attackers, with…
*-0.9.75
0.9.76
22/08/2022
Migration, Backup, Staging – WPvivid <= 0.9.75 – Authenticated (Admin+) Directory Traversal
The WPvivid plugin for WordPress is vulnerable to directory traversal in versions up to, and including, 0.9.75. This allows authenticated users with administrative privileges to download arbitrary files on the server, including sensitive configuration files, though the file…
*-0.9.75
0.9.76
16/08/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.