CVE-2026-19722: Unknown Wpvivid — Backup, Migration & Staging
Medium severity, CVSS 6.6. EPSS: 0.3% chance of exploitation in the next 30 days.
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, allowing high privilege users such as administrators to write arbitrary files outside the intended restore directory, which can lead to code execution.
Affected products
- Unknown Wpvivid — Backup, Migration & Staging: before 0.9.133 (fixed in 0.9.133)
Published 2026-08-30. Last modified 2026-09-03.