CVE-2026-82193 PUBLISHED

WPvivid Backup & Migration < 0.9.134 - Admin+ File Write Outside the Backup Directory via Path Traversal

Assigner: WPScan
Reserved: 28.08.2026 Published: 04.09.2026 Updated: 04.09.2026

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied file name before using it to build a write path, allowing administrators to write files of permitted types to arbitrary locations on the server and to overwrite existing files.

Product Status

Vendor Unknown
Product WPvivid — Backup, Migration & Staging
Versions Default: unaffected
  • affected from 0.9.113 to 0.9.134 (excl.)

Credits

  • reconnaissance finder
  • WPScan coordinator

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE