Impact
The WPvivid Backup, Migration & Staging plugin versions prior to 0.9.133 does not validate the destination paths of files extracted from a backup archive during restoration, which is a path traversal weakness (CWE-22). This flaw allows high‑privilege users such as administrators to write arbitrary files to locations outside the intended restore directory. If those files contain executable code, an attacker can achieve remote code execution on the web server. The vulnerability manifests as a Zip Slip condition where archive entries with relative paths escape the target directory.
Affected Systems
WordPress installations that use the WPvivid backup plugin with a version earlier than 0.9.133. The plugin, made by the vendor WPvivid, is the only affected component. Sites running these versions are vulnerable if administrators can restore backups from untrusted or externally supplied archives.
Risk and Exploitability
The CVSS score of 6.6 indicates moderate severity, but the potential impact of arbitrary file write and subsequent code execution remains high. The EPSS score is below 1%, indicating a low but non‑zero probability that the flaw will be exploited in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to have administrative or similarly privileged access to initiate a backup restore, or to coerce an administrator into restoring a malicious backup package. The risk is significant for sites that permit administrators to restore backups from arbitrary sources.
OpenCVE Enrichment