Impact
The WPvivid Backup, Migration & Staging plugin before version 0.9.133 fails to validate the destination paths of files extracted from a backup archive during restoration. This missing validation allows high‑privilege users, such as administrators, to write arbitrary files outside the intended restore directory. If such files contain executable code, the attacker can achieve code execution on the web server. The vulnerability is an example of a Zip Slip attack, where archive entries use relative paths to escape the target directory. Based on the description, the likely attack vector is that an attacker forces an administrator to restore a malicious backup package or already has administrative privileges to directly exploit the flaw.
Affected Systems
WordPress sites using the WPvivid Backup, Migration & Staging plugin at versions earlier than 0.9.133. The affected product is the WPvivid plugin itself; vendor information indicates it is an unknown vendor named WPvivid.
Risk and Exploitability
The CVSS score is not explicitly provided, but the impact of arbitrary file write leading to code execution suggests a high severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Exploitation requires users with administrative or other high‑privilege roles to initiate a backup restore. An attacker who can supply a crafted backup file or induce an admin to perform a restore can overwrite critical files, inject malware, or establish persistent access. The threat is significant for sites that allow administrators to restore backups from untrusted sources.
OpenCVE Enrichment