CVE-2025-12656

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in the delete_cancel_staging_site() function in all versions up to, and including, 0.9.128. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary folders on the server, which leads to a loss of data.
Configurations

No configuration.

History

23 Jul 2026, 07:10

Type Values Removed Values Added
Summary
  • (es) El plugin Migration, Backup, Staging - WPvivid Backup & Migration para WordPress es vulnerable a la eliminación arbitraria de directorios debido a una validación insuficiente de la ruta de archivo en la función delete_cancel_staging_site() en todas las versiones hasta la 0.9.128, ambas inclusive. Esto hace posible que atacantes autenticados, con acceso de nivel de Administrador y superior, eliminen carpetas arbitrarias en el servidor, lo que provoca una pérdida de datos.

06 Jun 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-06 00:16

Updated : 2026-07-23 07:10


NVD link : CVE-2025-12656

Mitre link : CVE-2025-12656

CVE.ORG link : CVE-2025-12656


JSON object : View

Products Affected

No product.

CWE
CWE-73

External Control of File Name or Path