Impact
The WPvivid — Backup, Migration & Staging WordPress plugin before version 0.9.134 does not validate a user‑supplied file name before using it to build a write path, allowing administrators to write files of permitted types to arbitrary locations on the server and to overwrite existing files. This weakness enables the dropping of malicious scripts or the replacement of critical configuration files, potentially leading to compromise of the WordPress installation.
Affected Systems
WordPress sites that have the WPvivid plugin installed with a version older than 0.9.134 are affected. The plugin is used by site administrators for backups and migrations. No other WordPress plugins or core components are impacted directly.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires administrative access to the WordPress site and occurs through the plugin’s file‑write endpoint that accepts an unsanitized file name, allowing attackers to overwrite files or drop new file types within the site’s file system.
OpenCVE Enrichment