CVE Database /
CVE-2025-12656
CVE · Low
CVE-2025-12656 — WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.129
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-12656
|
WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.129 |
External Control of File Name or Path |
Low
3.8
|
< 0.9.129
|
0.9.129 |
2026-06-05 |
—
|
CVE-2025-12656
The WPvivid Backup & Migration plugin contains a flaw that allows authorized users with elevated privileges to erase directories at will due to inadequate file path verification in its delete_cancel_staging_site function. This weakness is present in all plugin versions up to and including 0.9.128, enabling attackers to potentially cause data loss by deleting arbitrary folders on the server.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings