Impact
The WPvivid Backup & Migration plugin, when installed in a version older than 0.9.133, fails to properly sanitize a list of identifiers supplied by the user before inserting them into a SQL statement. This omission allows an authenticated administrator to inject arbitrary SQL code. An attacker can exploit this flaw to read or alter database contents, potentially compromising the integrity and confidentiality of the site.
Affected Systems
This issue affects the WordPress plugin WPvivid — Backup, Migration & Staging. Versions before 0.9.133 are vulnerable. No specific sub‑version details are provided beyond the threshold. The plugin is typically used on WordPress sites that require backup or migration capabilities.
Risk and Exploitability
The vulnerability is rated as a severe SQL injection flaw but no public CVSS score is available. Because the flaw requires an authenticated administrator account, the attack surface is restricted to sites with compromised or weak admin credentials. The EPSS score is not disclosed, and the vulnerability is not listed in the CISA KEV catalog, suggesting the likelihood of public exploitation is currently unknown but potentially high due to the ease of exploitation once admin access is obtained.
OpenCVE Enrichment