PLUGIN SECURITY

Is Wpvivid Backuprestore safe?

All-in-one WordPress backup, migration and staging plugin — schedule automatic backups, restore in one click, and migrate or clone sites safely.

What this plugin does

  • Slug: wpvivid-backuprestore
  • Author: wpvividplugins
  • 900000+ active installs
  • 98/100 rating (1534 reviews on wordpress.org)
  • 18789710 all-time downloads
  • On WordPress.org since 2019-01-04

backupcloneduplicatemigratestaging

Maintenance status

  • Latest known version: 0.9.132
  • Last updated: 2026-07-30 12:47am GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 5.3+
  • Max supported PHP (analyzed): <8.0

Known vulnerabilities

26 known CVEs on file for Wpvivid Backuprestore.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-19725 WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.131 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Unknown < 0.9.131 0.9.131 2026-08-16 ✓ fixed in latest
CVE-2026-17555 WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.132 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Medium 4.9 < 0.9.132 0.9.132 2026-07-31 ✓ fixed in latest
CVE-2025-12656 WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.129 External Control of File Name or Path Low 3.8 < 0.9.129 0.9.129 2026-06-05 ✓ fixed in latest
CVE-2025-12654 WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.121 External Control of File Name or Path Low 2.7 < 0.9.121 0.9.121 2025-12-20 ✓ fixed in latest
CVE-2024-13869 WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.113 Unrestricted Upload of File with Dangerous Type High 7.2 < 0.9.113 0.9.113 2025-02-21 ✓ fixed in latest
CVE-2024-56273 WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.107 Missing Authorization Medium 4.3 < 0.9.107 0.9.107 2025-01-03 ✓ fixed in latest
CVE-2024-10962 WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.108 Deserialization of Untrusted Data High 8.8 < 0.9.108 0.9.108 2024-11-13 ✓ fixed in latest
CVE-2024-7315 WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.106 Exposure of Sensitive Information to an Unauthorized Actor High 7.5 < 0.9.106 0.9.106 2024-09-11 ✓ fixed in latest
+ 35 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-3054 WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.100 Deserialization of Untrusted Data High 7.2 < 0.9.100 0.9.100 2024-04-11 ✓ fixed in latest
CVE-2024-1982, CVE-2024-1981 WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.69 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.1 < 0.9.69 0.9.69 2024-02-28 ✓ fixed in latest
CVE-2024-1981 WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.69 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.1 < 0.9.69 0.9.69 2024-02-28 ✓ fixed in latest
CVE-2023-4637 WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.95 Missing Authorization Medium 5.3 < 0.9.95 0.9.95 2024-01-19 ✓ fixed in latest
CVE-2023-5576 WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.92 Exposure of Sensitive Information to an Unauthorized Actor Critical 9.3 < 0.9.92 0.9.92 2023-10-13 ✓ fixed in latest
CVE-2023-5121 WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.90 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 0.9.90 0.9.90 2023-09-22 ✓ fixed in latest
CVE-2023-4274 WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.90 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 6.5 < 0.9.90 0.9.90 2023-09-22 ✓ fixed in latest
CVE-2023-5120 WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.90 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 0.9.90 0.9.90 2023-09-22 ✓ fixed in latest
WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.91 Unknown < 0.9.91 0.9.91 2023-09-13 ✓ fixed in latest
CVE-2023-41243 WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.91 Improper Privilege Management High 8.8 < 0.9.91 0.9.91 2023-09-12 ✓ fixed in latest
WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.77 Unknown < 0.9.77 0.9.77 2022-08-29 ✓ fixed in latest
WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.77 Unknown < 0.9.77 0.9.77 2022-08-29 ✓ fixed in latest
CVE-2022-2863 WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.76 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 4.9 < 0.9.76 0.9.76 2022-08-22 ✓ fixed in latest
WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.76 Unknown < 0.9.76 0.9.76 2022-08-16 ✓ fixed in latest
CVE-2022-2442 WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.76 Deserialization of Untrusted Data High 7.2 < 0.9.76 0.9.76 2022-08-10 ✓ fixed in latest
CVE-2022-27844 WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.71 Exposure of Sensitive Information to an Unauthorized Actor Low 2.7 < 0.9.71 0.9.71 2022-04-07 ✓ fixed in latest
CVE-2022-0531 WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.70 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 0.9.70 0.9.70 2022-03-21 ✓ fixed in latest
CVE-2021-24994 WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.71 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 0.9.71 0.9.71 2022-01-31 ✓ fixed in latest
WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.56 Unknown < 0.9.56 0.9.56 2021-08-09 ✓ fixed in latest
WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.53 Unknown < 0.9.53 0.9.53 2021-04-26 ✓ fixed in latest
CVE-2020-36835 WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.36 Exposure of Sensitive Information to an Unauthorized Actor Medium 4.9 < 0.9.36 0.9.36 2020-03-23 ✓ fixed in latest
CVE-2020-36842 WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.36 Unrestricted Upload of File with Dangerous Type High 8.8 < 0.9.36 0.9.36 2020-03-13 ✓ fixed in latest
WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.36 Unknown < 0.9.36 0.9.36 2020-02-28 ✓ fixed in latest
WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.117 Unrestricted Upload of File with Dangerous Type High 7.2 < 0.9.117 0.9.117 0000-00-00 ✓ fixed in latest
WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.124 Unknown < 0.9.124 0.9.124 0000-00-00 ✓ fixed in latest
WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.56 Unknown < 0.9.56 0.9.56 ✓ fixed in latest
WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.77 Unknown < 0.9.77 0.9.77 ✓ fixed in latest
WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.36 Unknown < 0.9.36 0.9.36 ✓ fixed in latest
WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.91 Unknown < 0.9.91 0.9.91 ✓ fixed in latest
WPvivid Backup < 0.9.36 - Missing Authorization Leading To Database Leak Unknown < 0.9.36 0.9.36 ✓ fixed in latest
WPvivid Backup < 0.9.56 - Reflected Cross-Site Scripting Unknown < 0.9.56 0.9.56 ✓ fixed in latest
WPvivid Backup 0.9.76 - Admin+ Arbitrary File Deletion Unknown < 0.9.77 0.9.77 ✓ fixed in latest
CVE-2023-41243 WPvivid Backup Plugin < 0.9.91 - Missing Authorization via 'start_staging' and 'get_staging_progress' Unknown < 0.9.91 0.9.91 ✓ fixed in latest
CVE-2025-5961 WPvivid Backup & Migration < 0.9.117 - Admin+ Arbitrary File Upload Unknown < 0.9.117 0.9.117 ✓ fixed in latest
CVE-2026-1357 Migration, Backup, Staging < 0.9.124 - Unauthenticated Arbitrary File Upload Unknown < 0.9.124 0.9.124 ✓ fixed in latest

How to fix it

Keep Wpvivid Backuprestore updated — 0.9.132 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.