Impact
The WPvivid Backup & Migration plugin, when installed in a version older than 0.9.133, fails to properly sanitize a list of identifiers supplied by the user before inserting them into a SQL statement. This omission allows an authenticated administrator to inject arbitrary SQL code. An attacker can exploit this flaw to read or alter database contents, potentially compromising the integrity and confidentiality of the site.
Affected Systems
This issue affects the WordPress plugin WPvivid — Backup, Migration & Staging. Versions before 0.9.133 are vulnerable. No specific sub‑version details are provided beyond the threshold. The plugin is typically used on WordPress sites that require backup or migration capabilities.
Risk and Exploitability
The vulnerability has a CVSS score of 4.1, indicating medium severity. The flaw requires an authenticated administrator account, so the attack surface is limited to sites with compromised or weak admin credentials. The EPSS score of less than 1% indicates a very low probability of public exploitation, and the vulnerability is not listed in the CISA KEV catalog. Thus, while the potential impact remains significant, exploitation is unlikely without admin access.
OpenCVE Enrichment