Description
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, allowing high privilege users such as administrators to write arbitrary files outside the intended restore directory, which can lead to code execution.
Published: 2026-08-30
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WPvivid Backup, Migration & Staging plugin before version 0.9.133 fails to validate the destination paths of files extracted from a backup archive during restoration. This missing validation allows high‑privilege users, such as administrators, to write arbitrary files outside the intended restore directory. If such files contain executable code, the attacker can achieve code execution on the web server. The vulnerability is an example of a Zip Slip attack, where archive entries use relative paths to escape the target directory. Based on the description, the likely attack vector is that an attacker forces an administrator to restore a malicious backup package or already has administrative privileges to directly exploit the flaw.

Affected Systems

WordPress sites using the WPvivid Backup, Migration & Staging plugin at versions earlier than 0.9.133. The affected product is the WPvivid plugin itself; vendor information indicates it is an unknown vendor named WPvivid.

Risk and Exploitability

The CVSS score is not explicitly provided, but the impact of arbitrary file write leading to code execution suggests a high severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Exploitation requires users with administrative or other high‑privilege roles to initiate a backup restore. An attacker who can supply a crafted backup file or induce an admin to perform a restore can overwrite critical files, inject malware, or establish persistent access. The threat is significant for sites that allow administrators to restore backups from untrusted sources.

Generated by OpenCVE AI on August 30, 2026 at 07:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the WPvivid plugin to version 0.9.133 or later to ensure proper destination path validation during backup restoration.
  • If an immediate upgrade is not possible, restrict the ability to restore backups to trusted administrators and verify all backup archives for malicious content before restoration.
  • Implement access controls and file integrity monitoring to detect unauthorized file creation or modification outside the WordPress root directory.

Generated by OpenCVE AI on August 30, 2026 at 07:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 30 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22

Sun, 30 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, allowing high privilege users such as administrators to write arbitrary files outside the intended restore directory, which can lead to code execution.
Title WPvivid Backup & Migration < 0.9.133 - Admin+ Arbitrary File Write via Zip Slip in Backup Restore
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-30T06:00:18.252Z

Reserved: 2026-08-13T12:06:08.098Z

Link: CVE-2026-19722

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-30T07:17:20.880

Modified: 2026-08-30T07:17:20.880

Link: CVE-2026-19722

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-30T07:30:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')