Input validation vulnerability in Migration, Backup, Staging – WPvivid Backup & Migration 0.9.107

The Migration, Backup, and Staging plugin for WordPress, called WPvivid, has a security issue in all versions up to 0.9.107. This means that unauthenticated attackers can inject a harmful PHP Object by taking advantage of the plugin’s code. There is no known way for them to do this automatically, but if there is another plugin or theme installed on the website, they can use that to delete files, access private information, or even run their own code. To trigger this issue, an administrator must first create a staging site.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.