PT-2026-73126 · WordPress · Wpvivid

·

CVE-2026-19725

·

Published

2026-08-16

·

Updated

2026-08-17

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions WPvivid — Backup, Migration & Staging WordPress plugin versions prior to 0.9.131
Description An issue exists where the plugin fails to sanitize a value from an unauthenticated request used to construct a log file path. An attacker possessing a site-to-site transfer key can exploit this to create a log file in any writable directory of the site, including the web root, via the send to site connect endpoint. The attacker controls the file location, although the file name includes a fixed suffix and the content is limited to the plugin's own log header.
Recommendations Update WPvivid — Backup, Migration & Staging WordPress plugin to version 0.9.131 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19725

Affected Products

Wpvivid