Arbitrary File Write Vulnerability in WPvivid Backup Plugin
CVE-2026-19722
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 30 August 2026
Badges
What is CVE-2026-19722?
The WPvivid Backup, Migration & Staging plugin for WordPress prior to version 0.9.133 is susceptible to an arbitrary file write vulnerability. This issue arises as the plugin fails to properly validate the destination paths for files extracted from backup packages during restoration. As a result, high-privilege users, such as administrators, may exploit this flaw to write files outside of the designated restore directory, potentially leading to unauthorized code execution on the server. Websites utilizing this plugin should be updated promptly to mitigate security risks.
Affected Version(s)
WPvivid β Backup, Migration & Staging 0 < 0.9.133
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.