CVE-2022-2442
The WPvivid backup and migration plugin contains a deserialization vulnerability affecting versions through 0.9.74 in the 'path' parameter that allows administrators to exploit PHAR wrappers to instantiate arbitrary PHP objects, potentially enabling malicious code execution if a suitable object chain exists and the attacker successfully uploads a file containing the serialized payload. Only authenticated users with administrative access can exploit this flaw. The vulnerability was patched in version 0.9.76.
Based on public CVE data (MITRE/NVD).