Description
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before using it in a file deletion routine, allowing administrators to delete arbitrary files on the server, including files outside the web root.
Published: 2026-09-04
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary file deletion by administrators
Action: Immediate Patch
AI Analysis

Impact

This vulnerability exists in the WPvivid — Backup, Migration & Staging WordPress plugin before version 0.9.134. The plugin does not validate user‑supplied paths before invoking a file deletion routine, allowing a user with administrative privileges to delete any file on the server, including files located outside the web root. This flaw is a path traversal issue that compromises data integrity and availability, as critical configuration or root files can be removed by the attacker.

Affected Systems

The affected product is the WPvivid plugin for WordPress, with all releases older than 0.9.134 vulnerable. No other vendors or product versions are listed. Administrators managing sites that run these versions are at risk.

Risk and Exploitability

The vulnerability requires administrator credentials to trigger the deletion routine, so it is not remotely exploitable by unauthenticated users. With a CVSS score of 5.5, the flaw presents moderate severity; the EPSS score of <1% and its not being listed in CISA KEV indicate that widespread exploitation is unlikely, yet may occur in targeted attacks. The impact is the ability to delete arbitrary files, including critical configuration or server files, which can compromise data integrity and availability. Prompt remediation by updating the plugin is recommended.

Generated by OpenCVE AI on September 4, 2026 at 17:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WPvivid plugin to version 0.9.134 or later, which addresses the path validation issue
  • If an upgrade is not feasible, disable or remove the file deletion feature so that no administrator can invoke it
  • Implement strict directory checks before any file operation to reject paths that navigate outside the intended root directory

Generated by OpenCVE AI on September 4, 2026 at 17:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22

Fri, 04 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpvividplugins
Wpvividplugins wpvivid — Backup, Migration & Staging
Vendors & Products Wordpress
Wordpress wordpress
Wpvividplugins
Wpvividplugins wpvivid — Backup, Migration & Staging

Fri, 04 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-73
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22

Fri, 04 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before using it in a file deletion routine, allowing administrators to delete arbitrary files on the server, including files outside the web root.
Title WPvivid Backup & Migration < 0.9.134 - Admin+ Arbitrary File Deletion via Path Traversal
References

Subscriptions

Wordpress Wordpress
Wpvividplugins Wpvivid — Backup, Migration & Staging
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-04T12:44:32.515Z

Reserved: 2026-08-28T07:51:22.016Z

Link: CVE-2026-82194

cve-icon Vulnrichment

Updated: 2026-09-04T12:44:26.056Z

cve-icon NVD

Status : Deferred

Published: 2026-09-04T07:17:10.840

Modified: 2026-09-08T19:15:18.627

Link: CVE-2026-82194

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T18:00:04Z

Weaknesses
  • CWE-73

    External Control of File Name or Path