CVE-2026-82194 PUBLISHED

WPvivid Backup & Migration < 0.9.134 - Admin+ Arbitrary File Deletion via Path Traversal

Assigner: WPScan
Reserved: 28.08.2026 Published: 04.09.2026 Updated: 04.09.2026

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before using it in a file deletion routine, allowing administrators to delete arbitrary files on the server, including files outside the web root.

Product Status

Vendor Unknown
Product WPvivid — Backup, Migration & Staging
Versions Default: unaffected
  • affected from 0 to 0.9.134 (excl.)

Credits

  • Meher Sudhakar Abbireddi finder
  • WPScan coordinator

References

Problem Types

  • CWE-73 External Control of File Name or Path CWE