THREAT OPS › Threat News › [NVD] CVE-2026-17555 (MEDIUM 4.9) — The WPvivid Backup & Migration plugin for WordPress is vulnerable to SQL Injection via the export_data parameter in versions up to, and including, 0.9.131. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL q
[NVD] CVE-2026-17555 (MEDIUM 4.9) — The WPvivid Backup & Migration plugin for WordPress is vulnerable to SQL Injection via the export_data parameter in versions up to, and including, 0.9.131. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL q
CVE-2026-17555 CVSS: 4.9 MEDIUM Published: 2026-08-01T09:17:01.397
The WPvivid Backup & Migration plugin for WordPress is vulnerable to SQL Injection via the export_data parameter in versions up to, and including, 0.9.131. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. The values are received in prepare_export_post
Indicators of compromise
- CVE-2026-17555cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-17555