PT-2026-83524 · WordPress · Wpvivid
CVSS v3.1
6.6
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
WPvivid — Backup, Migration & Staging versions prior to 0.9.133
Description
The backup restoration process fails to properly validate the destination paths of files extracted from a backup package. This creates a Zip Slip condition, which is a type of path-traversal vulnerability where a crafted archive can force files to be written outside the intended restoration directory. High-privilege users, such as administrators, can exploit this to write arbitrary files elsewhere on the server, potentially leading to server-side code execution if executable content is placed in a web-accessible location.
Recommendations
Update to version 0.9.133 or newer.
Review users authorized to initiate backup restorations.
Inspect recently restored archives and check for files created outside expected WordPress directories.
Inspect
wp-content/plugins and wp-content/uploads for unexpected executable files.
Review web-server logs related to recent restore operations.
Restrict administrative WordPress accounts using multi-factor authentication (MFA).Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wpvivid