Arbitrary File Write Vulnerability in WPvivid Backup Plugin
CVE-2026-19722

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
30 August 2026

Badges

πŸ‘Ύ Exploit Exists🟑 Public PoC

What is CVE-2026-19722?

The WPvivid Backup, Migration & Staging plugin for WordPress prior to version 0.9.133 is susceptible to an arbitrary file write vulnerability. This issue arises as the plugin fails to properly validate the destination paths for files extracted from backup packages during restoration. As a result, high-privilege users, such as administrators, may exploit this flaw to write files outside of the designated restore directory, potentially leading to unauthorized code execution on the server. Websites utilizing this plugin should be updated promptly to mitigate security risks.

Affected Version(s)

WPvivid β€” Backup, Migration & Staging 0 < 0.9.133

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nir Yehoshua
WPScan
.