Unauthorized File Creation Vulnerability in WPvivid Backup, Migration & Staging Plugin
CVE-2026-19725
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 August 2026
Badges
What is CVE-2026-19725?
The WPvivid β Backup, Migration & Staging WordPress plugin prior to version 0.9.131 contains a vulnerability that allows an unauthenticated attacker, armed with a site-to-site transfer key, to manipulate log file paths. This occurs due to inadequate sanitization of inputs, enabling the attacker to create log files in any writable directory, including the web root. The log filename structure remains constant, but the location is entirely under the attacker's control, posing significant security risks for affected installations.
Affected Version(s)
WPvivid β Backup, Migration & Staging 0 < 0.9.131
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.