CVE-2026-82194: Unknown Wpvivid — Backup, Migration & Staging
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before using it in a file deletion routine, allowing administrators to delete arbitrary files on the server, including files outside the web root.
Affected products
- Unknown Wpvivid — Backup, Migration & Staging: before 0.9.134 (fixed in 0.9.134)
Published 2026-09-04. Last modified 2026-09-08.