File Write Vulnerability in WPvivid Plugin by WPvivid Team
CVE-2026-82193

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
4 September 2026

Badges

πŸ‘Ύ Exploit Exists🟑 Public PoC

What is CVE-2026-82193?

The WPvivid Backup, Migration & Staging plugin for WordPress allows an attacker with administrative access to exploit insufficient validation of user-supplied file names. This leads to arbitrary file write capabilities, permitting administrators to save files to unintended locations on the server, which may include overwriting critical existing files. Such a flaw compromises the integrity of file management and could potentially lead to unauthorized access and manipulation of sensitive data.

Affected Version(s)

WPvivid β€” Backup, Migration & Staging 0.9.113 < 0.9.134

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

reconnaissance
WPScan
.