SQL Injection Risk in WPvivid Backup & Migration Plugin for WordPress
CVE-2026-17555

4.9MEDIUM

What is CVE-2026-17555?

The WPvivid Backup & Migration plugin for WordPress is susceptible to SQL Injection through the export_data parameter. This vulnerability arises from inadequate sanitization of user-supplied input and improper handling of SQL queries. Attackers, possessing Administrator-level access or higher, can exploit this weakness by inserting additional SQL queries into existing ones through arguments passed to the plugin's functions. Such exploitation can lead to unauthorized access to sensitive database information, emphasizing the need for immediate updates and robust security practices to mitigate this risk.

Affected Version(s)

WPvivid β€” Backup, Migration & Staging 0 <= 0.9.131

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.