WPvivid — Backup, Migration & Staging

WPvivid — Backup, Migration & Staging has 33 disclosed vulnerabilities in the WordSec catalog, reported between 2020 and 2026; all 33 are fixed as of September 2026. Their average CVSS score is 6.5, and the most serious one scores 9.8 out of 10. Severity breakdown: 2 critical and 13 high. 2026 was the busiest year with 8 disclosures.

The most common weakness is Cross-Site Scripting, behind 5 of the records (15%). Other recurring categories include Path Traversal, Unrestricted Upload Of File With Dangerous Type.

Every one of the 33 issues recorded for WPvivid — Backup, Migration & Staging has a vendor fix available, so running the current release closes all known holes.

22 independent researchers contributed these findings, most of them (3) reported by Ivan Kuzymchak. WPvivid — Backup, Migration & Staging is installed on roughly 900,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

01234567891004.01.2019Today13.03.20208.8Migration, Backup, Staging – WPvivid <= 0.9.35 - Authenticated (Subscriber+) Arbitrary File Upload CVSS 8.8 · 13.03.202023.03.20204.9Migration, Backup, Staging – WPvivid <= 0.9.35 - Sensitive Information Disclosure CVSS 4.9 · 23.03.202009.08.20216.1Migration, Backup, Staging – WPvivid <= 0.9.55 - Reflected Cross-Site Scripting CVSS 6.1 · 09.08.202131.01.20226.1Migration, Backup, Staging – WPvivid <= 0.9.68 - Unauthenticated Stored Cross-Site Scripting CVSS 6.1 · 31.01.202221.03.20226.1Migration, Backup, Staging – WPvivid <= 0.9.69 - Reflected Cross-Site Scripting via sub_page Parameter CVSS 6.1 · 21.03.202207.04.20224.9Migration, Backup, Staging – WPvivid <= 0.9.70 - Authenticated Arbitrary File Read CVSS 4.9 · 07.04.202210.08.20227.2Migration, Backup, Staging – WPvivid <= 0.9.74 - Authenticated (Admin+) PHAR Deserialization CVSS 7.2 · 10.08.202216.08.20226.0Migration, Backup, Staging – WPvivid <= 0.9.75 - Authenticated (Admin+) Directory Traversal CVSS 6.0 · 16.08.202222.08.20226.5Migration, Backup, Staging – WPvivid <= 0.9.75 - Authenticated (Administrator+) Path Traversal CVSS 6.5 · 22.08.202229.08.20226.5WPvivid Backup 0.9.76 - Authenticated (Administrator+) Arbitrary File Deletion CVSS 6.5 · 29.08.202212.09.20238.3WPvivid Backup Plugin <= 0.9.90 - Missing Authorization via 'start_staging' and 'get_staging_progress' CVSS 8.3 · 12.09.202322.09.20238.7Migration, Backup, Staging – WPvivid <= 0.9.89 - Authenticated (Administrator+) Arbitrary Directory Deletion via Path Traversal CVSS 8.7 · 22.09.20234.4Migration, Backup, Staging – WPvivid <= 0.9.89 - Authenticated Stored Cross-Site Scripting CVSS 4.4 · 22.09.20234.4Migration, Backup, Staging – WPvivid <= 0.9.89 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 22.09.202313.10.20238.0Migration, Backup, Staging – WPvivid <= 0.9.91 - Google Drive Client Secret Exposure CVSS 8.0 · 13.10.202319.01.20244.3WPvivid <= 0.9.94 - Missing Authorization CVSS 4.3 · 19.01.202428.02.20246.5WPvivid Backup and Migration <= 0.9.68 - Missing Authorization CVSS 6.5 · 28.02.20249.8WPvivid Backup and Migration <= 0.9.68 - Unauthenticated SQL Injection CVSS 9.8 · 28.02.202411.04.20247.2WPvivid Backup & Migration Plugin <= 0.9.99 - Authenticated (Admin+) PHAR Deserialization CVSS 7.2 · 11.04.202411.09.20247.5Migration, Backup, Staging – WPvivid <= 0.9.105 - Sensitive Information Exposure CVSS 7.5 · 11.09.202413.11.20248.8Migration, Backup, Staging – WPvivid <= 0.9.107 - Unauthenticated PHP Object Injection CVSS 8.8 · 13.11.202403.01.20255.3WPvivid Backup and Migration <= 0.9.106 - Missing Authorization CVSS 5.3 · 03.01.202521.02.20257.2Migration, Backup, Staging – WPvivid <= 0.9.112 - Authenticated (Admin+) Arbitrary File Upload via wpvivid_upload_file CVSS 7.2 · 21.02.202503.07.20257.2Migration, Backup, Staging – WPvivid Backup & Migration <= 0.9.116 - Authenticated (Administrator+) Arbitrary File Upload CVSS 7.2 · 03.07.202520.12.20252.7Migration, Backup, Staging – WPvivid Backup & Migration <= 0.9.120 - Authenticated (Admin+) Arbitrary Directory Creation CVSS 2.7 · 20.12.202510.02.20269.8Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload CVSS 9.8 · 10.02.202605.06.20263.8Migration, Backup, Staging – WPvivid Backup & Migration <= 0.9.128 - Authenticated (Admin+) Arbitrary Directory Deletion CVSS 3.8 · 05.06.202631.07.20264.9WPvivid <= 0.9.131 - Authenticated (Administrator+) SQL Injection via 'export_data' Parameter CVSS 4.9 · 31.07.202620.08.20267.5WPvivid — Backup, Migration & Staging < 0.9.131 - Unauthenticated Path Traversal CVSS 7.5 · 20.08.202630.08.20267.2WPvivid — Backup, Migration & Staging < 0.9.133 - Authenticated (Administrator+) Remote Code Execution CVSS 7.2 · 30.08.202602.09.20266.5WPvivid — Backup, Migration & Staging < 0.9.134 - Authenticated (Administrator+) Arbitrary File Deletion CVSS 6.5 · 02.09.20264.9WPvivid — Backup, Migration & Staging < 0.9.133 - Authenticated (Administrator+) SQL Injection CVSS 4.9 · 02.09.20267.2WPvivid — Backup, Migration & Staging < 0.9.134 - Authenticated (Administrator+) Arbitrary File Upload CVSS 7.2 · 02.09.2026

Strategic Overview

Avg CVSSMedium
6.5/ 10
Patch Coverage100%
Open

0

Fixed

33

Get automatic notifications for all WPvivid — Backup, Migration & Staging vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2026-1357

Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload

Read the full analysis

Vulnerability Records

33 records
2026-09-02 00:00CVE-2026-82194
6.5
Medium
Meher Sudhakar AbbireddiYes
2026-09-02 00:00CVE-2026-82182
4.9
Medium
cyberkareemYes
2026-09-02 00:00CVE-2026-82193
7.2
High
reconnaissanceYes
2026-08-30 00:00CVE-2026-19722
7.2
High
Nir YehoshuaYes
2026-08-20 00:00CVE-2026-19725
7.5
High
Nir YehoshuaYes
2026-07-31 19:54CVE-2026-17555
4.9
Medium
Wordfence PRISMYes
2026-06-05 10:43CVE-2025-12656
3.8
Low
blue0x1Yes
2026-02-10 17:13CVE-2026-1357
9.8
Critical
Lucas Montes (NiRoX)Yes
2025-12-20 14:45CVE-2025-12654
2.7
Low
blue0x1Yes
2025-07-03 00:35CVE-2025-5961
7.2
High
Ryan KozakYes
Showing 1–10 of 33 reports
WPvivid — Backup, Migration & Staging banner
Latestv0.9.135

WPvivid — Backup, Migration & Staging

wpvividplugins

Author

wpvividplugins

4.9(1,546)
98/100
Last Updated
2026-09-10 (3d ago)
Active Installs
900,000+
Downloads
19,569,008
Requires WP
4.5+
Requires PHP
5.3+
Tested up to
WP 7.1
Created
2019-01-04 (8y ago)

WPvivid Backup & Migration Plugin offers backup, migration, and staging (create a staging site on a subdirectory to safely test WordPress, plugins, themes and website changes) as basic features. WPvivid Backup & Migration for MainWP WPvivid Backup & Migration for MainWP is now available to download. WPvivid Backup & Migration for MainWP allows you to set up and control WPvivid Backup & Migration plugins for all child sites directly from your MainWP dashboard. WPvivid Backup & Migration Pro is Now Available Customize everything to backup Create staging sites and push staging sites to live Incremental backups Database backup encryption Auto backup WordPress, themes, and plugins WordPress multisite backup WordPress multisite staging Create a fresh WP install Advanced remote backups Advanced backup schedules Restore remote backups Migrate a site via remote storage Migrate a childsite (MU) to a single WordPress install White label WPvivid Backup & Migration Pro Control user access to WPvivid Backup & Migration Pro More amazing features See a review video on WPvivid Backup & Migration Pro: Get WPvivid Backup & Migration Pro Core Features 1. Easy Backups Easily create a backup of your WordPress site. You can choose to backup the entire site(database+files), all files, or database only. 2. Auto Migration Clone and migrate your WordPress site to a new domain with a single click. WPvivid Backup & Migration Plugin supports site migration from dev environment to a new server, from dev environment to a new domain or from a live server to another. 3. Create A Staging Site Create a staging site on a subdirectory of your production site to safely test WordPress, plugins, themes and website changes. You can choose what to copy from the the live site to the staging site. 4. Scheduled Backups Set a schedule to run backups automatically on your website. You can set the backups to run every 12 hours, daily, weekly, fortnightly, monthly, choose backup items and destination. 5. Offsite Backup to Remote Storage Send your backups offsite to a remote location. WPvivid Backup & Migration Plugin supports the leading cloud storage providers: Dropbox, Google Drive, Amazon S3, Microsoft OneDrive, DigitalOcean Spaces, FTP and SFTP. 6. One-Click Restore Restore your WordPress site from a backup with a single click. 7. Cloud Storage Supported WPvivid Backup & Migration plugin supports Dropbox, Google Drive, Microsoft OneDrive, Amazon S3, DigitalOcean Spaces, SFTP, FTP. WPvivid Backup & Migration Pro also supports Wasabi, pCloud, Backblaze, WebDav and more. Minimum Requirements to use WPvivid Backup & Migration plugin Character Encoding UTF-8 PHP version 5.3 MySQL version 4.1 WordPress 4.5 External Services This plugin can optionally connect to third-party storage providers — Google Drive, Dropbox, Microsoft OneDrive, Amazon S3, DigitalOcean Spaces, and FTP/SFTP servers — to store backup files. When remote storage is enabled, backup archives and required authentication tokens are sent to the selected service’s API. Use of these services is subject to their own terms and privacy policies.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C