CVE-2026-19725
Received Received - Intake

Path Traversal in WPvivid Backup Plugin

Vulnerability report for CVE-2026-19725, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-16

Last updated on: 2026-08-16

Assigner: WPScan

Description

The WPvivid β€” Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an unauthenticated request before using it to build a log file path, allowing an attacker holding a site to site transfer key to create a log file in any existing writable directory of the site, including the web root. The file name always carries a fixed suffix and the contents are always the WPvivid β€” Backup, Migration & Staging WordPress plugin before 0.9.131's own log header, so only the location of the file is attacker controlled.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-16
Last Modified
2026-08-16
Generated
2026-08-16
AI Q&A
2026-08-16
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wpvivid backup_migration_and_staging to 0.9.131 (exc)
wpscan wpvivid_backup_migration_staging to 0.9.131 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a path traversal issue in the WPvivid Backup & Migration WordPress plugin before version 0.9.131. It allows an attacker with a site-to-site transfer key to write a log file to any writable directory on the server, including the web root. The file name has a fixed suffix and content is always the plugin's log header, meaning only the file's location is controlled by the attacker.

Detection Guidance

Check for unexpected log files in web directories or writable folders with names containing the fixed suffix mentioned in the vulnerability details. Review server logs for unusual file creation events in sensitive directories.

Impact Analysis

An attacker could place malicious files in critical directories, potentially overwriting existing files or creating files that could be used for further attacks. This could lead to website defacement, data corruption, or unauthorized access to sensitive information.

Compliance Impact

This vulnerability could lead to unauthorized file creation or modification, potentially violating data integrity and confidentiality requirements under GDPR and HIPAA. It may result in non-compliance if sensitive data is exposed or altered.

Mitigation Strategies

Update the WPvivid Backup & Migration plugin to version 0.9.131 or later immediately. If updating is not possible, restrict write permissions on web directories and disable site-to-site transfer keys until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19725. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart