Wpvivid develops WordPress backup, migration, and staging plugins that are widely embedded across WordPress site management and hosting infrastructure, presenting a supply-chain attack surface disproportionate to its narrow product count. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability, reflecting both the plugins' administrative access and their prevalence in WordPress deployments. The exposure recurs across its backup and migration product lines through weakness classes including cross-site scripting, missing authorization, untrusted deserialization, sensitive-information disclosure, and path traversal—a pattern characteristic of plugins handling file operations, user inputs, and privileged data movement. Defenders should treat Wpvivid plugin updates as high-priority across their WordPress infrastructure, especially for internet-exposed administrative interfaces; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpvivid over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-3054HIGH WPvivid Backup & Migration Plugin for WordPress is vulnerable to PHAR Deserialization in all versions up to, and including, 0.9.99 via deserialization of untrusted input at the wpv | Apr 12, 2024 | 7.2 | 41 | NO | NO |
CVE-2022-2863MEDIUM The Migration, Backup, Staging WordPress plugin before 0.9.76 does not sanitise and validate a parameter before using it to read the content of a file, allowing high privilege user | Sep 16, 2022 | 4.9 | 39 | NO | YES |
CVE-2025-5961HIGH The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpvivid_upload_ | Jul 3, 2025 | 7.2 | 35 | NO | YES |
CVE-2023-5576CRITICAL The Migration, Backup, Staging - WPvivid plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 0.9.91 via Google Drive API secrets | Oct 20, 2023 | 9.3 | 29 | NO | NO |
CVE-2024-1982CRITICAL The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the get_restore_progress() and restore() fun | Feb 29, 2024 | 9.1 | 28 | NO | NO |
CVE-2020-36842HIGH The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the wpvivid_upload_import_files and wpviv | Oct 16, 2024 | 8.8 | 27 | NO | NO |
CVE-2024-56273CRITICAL Missing Authorization vulnerability in wpvividplugins WPvivid Backup and Migration wpvivid-backuprestore allows Accessing Functionality Not Properly Constrained by ACLs.This issue | Jan 7, 2025 | 9.8 | 25 | NO | NO |
CVE-2024-10962HIGH The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.9.107 via deserialization of untrusted i | Nov 14, 2024 | 8.8 | 25 | NO | NO |
CVE-2023-41243HIGH Improper Privilege Management vulnerability in WPvivid Team WPvivid Backup and Migration allows Privilege Escalation.This issue affects WPvivid Backup and Migration: from n/a throu | May 17, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-1981CRITICAL The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to SQL Injection via the 'table_prefix' parameter in version 0.9.68 due to insufficient escaping on the | Feb 29, 2024 | 9.1 | 25 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpvivid.
Media articles that mention a CVE ID that affects a product developed by Wpvivid — matched by CVE ID, not by vendor name.