PT-2026-83524 · WordPress · Wpvivid

·

CVE-2026-19722

·

Published

2026-08-30

·

Updated

2026-09-03

CVSS v3.1

6.6

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions WPvivid — Backup, Migration & Staging versions prior to 0.9.133
Description The backup restoration process fails to properly validate the destination paths of files extracted from a backup package. This creates a Zip Slip condition, which is a type of path-traversal vulnerability where a crafted archive can force files to be written outside the intended restoration directory. High-privilege users, such as administrators, can exploit this to write arbitrary files elsewhere on the server, potentially leading to server-side code execution if executable content is placed in a web-accessible location.
Recommendations Update to version 0.9.133 or newer. Review users authorized to initiate backup restorations. Inspect recently restored archives and check for files created outside expected WordPress directories. Inspect wp-content/plugins and wp-content/uploads for unexpected executable files. Review web-server logs related to recent restore operations. Restrict administrative WordPress accounts using multi-factor authentication (MFA).

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19722

Affected Products

Wpvivid