CVE-2026-19722 PUBLISHED

WPvivid Backup & Migration < 0.9.133 - Admin+ Arbitrary File Write via Zip Slip in Backup Restore

Assigner: WPScan
Reserved: 13.08.2026 Published: 30.08.2026 Updated: 30.08.2026

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, allowing high privilege users such as administrators to write arbitrary files outside the intended restore directory, which can lead to code execution.

Product Status

Vendor Unknown
Product WPvivid — Backup, Migration & Staging
Versions Default: unaffected
  • affected from 0 to 0.9.133 (excl.)

Credits

  • Nir Yehoshua finder
  • WPScan coordinator

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE