Unauthorized File Creation Vulnerability in WPvivid Backup, Migration & Staging Plugin
CVE-2026-19725

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
16 August 2026

Badges

πŸ‘Ύ Exploit Exists🟑 Public PoC

What is CVE-2026-19725?

The WPvivid β€” Backup, Migration & Staging WordPress plugin prior to version 0.9.131 contains a vulnerability that allows an unauthenticated attacker, armed with a site-to-site transfer key, to manipulate log file paths. This occurs due to inadequate sanitization of inputs, enabling the attacker to create log files in any writable directory, including the web root. The log filename structure remains constant, but the location is entirely under the attacker's control, posing significant security risks for affected installations.

Affected Version(s)

WPvivid β€” Backup, Migration & Staging 0 < 0.9.131

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nir Yehoshua
WPScan
.