← Back to CVE List
Vulnerability Intelligence Report
WPvivid Backup & Migration < 0.9.131 - Unauthenticated Path Traversal via send_to_site_connect

CVE-2026-19725

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an unauthenticated request before using it to build a log file path, allowing an attacker holding a site to site transfer key to create a log file in any existing writable directory of the site, including the web root. The file name always carries a fixed suffix and the contents are always the WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131's own log header, so only the location of the file is attacker controlled.

No Active Exploit Signals
CVSS Base Score
9.1
CRITICAL
Exploitability:3.9
Impact Score:5.2
EPSS Probability:0.16%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-22 ↗CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Affected Products & Versions

Vendor Product Affected Versions
Unknown WPvivid — Backup, Migration & Staging 0 < 0.9.131 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.160%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityWPScan · Vendor · France
Reserved2026-08-13T12:24:20
Published2026-08-16T06:00:16
Last Updated2026-08-17T20:07:51

LINK COPIED TO CLIPBOARD