Impact
The WPvivid – Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitize a value received from an unauthenticated request before using it to construct a log file path. The file name has a fixed suffix and the contents are always the plugin’s log header, meaning only the file location is controlled by the attacker. An attacker who possesses a site‑to‑site transfer key can trigger the flawed endpoint and create a file in any existing writable directory on the WordPress instance, including the web root.
Affected Systems
Any WordPress installation running the WPvivid plugin with a version earlier than 0.9.131 is vulnerable. The flaw applies regardless of the presence or absence of other plugins or themes.
Risk and Exploitability
The CVSS score is 9.1, EPSS <1%, and the vulnerability is not listed in KEV. The attack vector is an unauthenticated HTTP request that carries a site‑to‑site transfer key already available to the site operator. The attacker can write a file to any existing writable directory on the WordPress site; while the file contents are fixed, placing a file inside the web root or other writable location could be leveraged in conjunction with other weaknesses to facilitate code execution or persistence.
OpenCVE Enrichment