CVE · Low

CVE-2025-12656 — WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.129

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-12656 WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.129 External Control of File Name or Path Low 3.8 < 0.9.129 0.9.129 2026-06-05

CVE-2025-12656

The WPvivid Backup & Migration plugin contains a flaw that allows authorized users with elevated privileges to erase directories at will due to inadequate file path verification in its delete_cancel_staging_site function. This weakness is present in all plugin versions up to and including 0.9.128, enabling attackers to potentially cause data loss by deleting arbitrary folders on the server.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.