CVE-2026-19722
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup
CVSS
—
No CVSS
EPSS
0.2%
p7
KEV
—
Exploit Today
2
0-100
Published: Aug 30, 2026 · Last modified: Aug 30, 2026
Not enough EPSS history yet.
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, allowing high privilege users such as administrators to write arbitrary files outside the intended restore directory, which can lead to code execution.
No related CVEs by CWE or product.