Impact
This vulnerability exists in the WPvivid — Backup, Migration & Staging WordPress plugin before version 0.9.134. The plugin does not validate user‑supplied paths before invoking a file deletion routine, allowing a user with administrative privileges to delete any file on the server, including files located outside the web root. This flaw is a path traversal issue that compromises data integrity and availability, as critical configuration or root files can be removed by the attacker.
Affected Systems
The affected product is the WPvivid plugin for WordPress, with all releases older than 0.9.134 vulnerable. No other vendors or product versions are listed. Administrators managing sites that run these versions are at risk.
Risk and Exploitability
The vulnerability requires administrator credentials to trigger the deletion routine, so it is not remotely exploitable by unauthenticated users. With a CVSS score of 5.5, the flaw presents moderate severity; the EPSS score of <1% and its not being listed in CISA KEV indicate that widespread exploitation is unlikely, yet may occur in targeted attacks. The impact is the ability to delete arbitrary files, including critical configuration or server files, which can compromise data integrity and availability. Prompt remediation by updating the plugin is recommended.
OpenCVE Enrichment