SQL Injection Risk in WPvivid Backup & Migration Plugin for WordPress
CVE-2026-17555
4.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 August 2026
What is CVE-2026-17555?
The WPvivid Backup & Migration plugin for WordPress is susceptible to SQL Injection through the export_data parameter. This vulnerability arises from inadequate sanitization of user-supplied input and improper handling of SQL queries. Attackers, possessing Administrator-level access or higher, can exploit this weakness by inserting additional SQL queries into existing ones through arguments passed to the plugin's functions. Such exploitation can lead to unauthorized access to sensitive database information, emphasizing the need for immediate updates and robust security practices to mitigate this risk.
Affected Version(s)
WPvivid β Backup, Migration & Staging 0 <= 0.9.131