Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wpvivid

First CVE: Feb 28, 2022Active for: 4 yearsTotal CVEs: 23
48.3
VTI Score
High

Wpvivid develops WordPress backup, migration, and staging plugins that are widely embedded across WordPress site management and hosting infrastructure, presenting a supply-chain attack surface disproportionate to its narrow product count. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability, reflecting both the plugins' administrative access and their prevalence in WordPress deployments. The exposure recurs across its backup and migration product lines through weakness classes including cross-site scripting, missing authorization, untrusted deserialization, sensitive-information disclosure, and path traversal—a pattern characteristic of plugins handling file operations, user inputs, and privileged data movement. Defenders should treat Wpvivid plugin updates as high-priority across their WordPress infrastructure, especially for internet-exposed administrative interfaces; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
23
Total CVEs
More Total CVEs than 96% of tracked vendors
1.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wpvivid over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 28, 2022
4 years ago
Most Recent CVE
Jul 3, 2025
386 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-3054HIGH
WPvivid Backup & Migration Plugin for WordPress is vulnerable to PHAR Deserialization in all versions up to, and including, 0.9.99 via deserialization of untrusted input at the wpv
Apr 12, 20247.241NONO
CVE-2022-2863MEDIUM
The Migration, Backup, Staging WordPress plugin before 0.9.76 does not sanitise and validate a parameter before using it to read the content of a file, allowing high privilege user
Sep 16, 20224.939NOYES
CVE-2025-5961HIGH
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpvivid_upload_
Jul 3, 20257.235NOYES
CVE-2023-5576CRITICAL
The Migration, Backup, Staging - WPvivid plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 0.9.91 via Google Drive API secrets
Oct 20, 20239.329NONO
CVE-2024-1982CRITICAL
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the get_restore_progress() and restore() fun
Feb 29, 20249.128NONO
CVE-2020-36842HIGH
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the wpvivid_upload_import_files and wpviv
Oct 16, 20248.827NONO
CVE-2024-56273CRITICAL
Missing Authorization vulnerability in wpvividplugins WPvivid Backup and Migration wpvivid-backuprestore allows Accessing Functionality Not Properly Constrained by ACLs.This issue
Jan 7, 20259.825NONO
CVE-2024-10962HIGH
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.9.107 via deserialization of untrusted i
Nov 14, 20248.825NONO
CVE-2023-41243HIGH
Improper Privilege Management vulnerability in WPvivid Team WPvivid Backup and Migration allows Privilege Escalation.This issue affects WPvivid Backup and Migration: from n/a throu
May 17, 20248.825NONO
CVE-2024-1981CRITICAL
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to SQL Injection via the 'table_prefix' parameter in version 0.9.68 due to insufficient escaping on the
Feb 29, 20249.125NONO
View all 23 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products23 CVEs
43%
39%
17%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network23 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None15 (65.2%)
Unknown0 (0.0%)
Required8 (34.8%)
Privileges Required
Low3 (13.0%)
High8 (34.8%)
None12 (52.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
8.7% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wpvivid.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wpvivid — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wpvivid's Products

View all 3 CNAs →

Top CWEs