CVE-2026-82182: WPvivid Backup & Migration < 0.9.133 - Admin+ SQLi via Upload Cleaner Isolation
Published Sep 2, 2026
·Updated
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not sanitise a user supplied list of identifiers before using it in a SQL query, allowing administrators to perform SQL injection attacks.
Affected Software
1 affected component
WPvivid WPvivid — Backup, Migration & Staging<0.9.133
Event History
Sep 2, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Exploitation requires administrator-level access to the affected WordPress site. The available information does not indicate that lower-privileged or unauthenticated users can exploit it.
2
Which installations are affected?
WPvivid Backup, Migration & Staging versions before 0.9.133 are affected. Upgrade the plugin to version 0.9.133 or later.
3
What input is vulnerable?
The issue involves a user-supplied list of identifiers used by the Upload Cleaner Isolation functionality. Those identifiers are not sanitised before being incorporated into a SQL query.