Description
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied file name before using it to build a write path, allowing administrators to write files of permitted types to arbitrary locations on the server and to overwrite existing files.
Published: 2026-09-04
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary file write
Action: Patch Now
AI Analysis

Impact

The WPvivid — Backup, Migration & Staging WordPress plugin before version 0.9.134 does not validate a user‑supplied file name before using it to build a write path, allowing administrators to write files of permitted types to arbitrary locations on the server and to overwrite existing files. This weakness enables the dropping of malicious scripts or the replacement of critical configuration files, potentially leading to compromise of the WordPress installation.

Affected Systems

WordPress sites that have the WPvivid plugin installed with a version older than 0.9.134 are affected. The plugin is used by site administrators for backups and migrations. No other WordPress plugins or core components are impacted directly.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires administrative access to the WordPress site and occurs through the plugin’s file‑write endpoint that accepts an unsanitized file name, allowing attackers to overwrite files or drop new file types within the site’s file system.

Generated by OpenCVE AI on September 4, 2026 at 22:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WPvivid to version 0.9.134 or later
  • Disable or uninstall the WPvivid plugin if not required
  • Limit plugin usage to trusted administrators and remove elevated rights

Generated by OpenCVE AI on September 4, 2026 at 22:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Fri, 04 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpvividplugins
Wpvividplugins wpvivid — Backup, Migration & Staging
Vendors & Products Wordpress
Wordpress wordpress
Wpvividplugins
Wpvividplugins wpvivid — Backup, Migration & Staging

Fri, 04 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-22

Fri, 04 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied file name before using it to build a write path, allowing administrators to write files of permitted types to arbitrary locations on the server and to overwrite existing files.
Title WPvivid Backup & Migration < 0.9.134 - Admin+ File Write Outside the Backup Directory via Path Traversal
References

Subscriptions

Wordpress Wordpress
Wpvividplugins Wpvivid — Backup, Migration & Staging
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-04T12:45:21.897Z

Reserved: 2026-08-28T07:51:19.951Z

Link: CVE-2026-82193

cve-icon Vulnrichment

Updated: 2026-09-04T12:45:17.105Z

cve-icon NVD

Status : Deferred

Published: 2026-09-04T07:17:10.743

Modified: 2026-09-08T19:15:18.627

Link: CVE-2026-82193

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T22:15:06Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')