CVE-2026-19725

CRITICAL CVSS 3.1: 9.1 EPSS 0.16%
Updated Aug 17, 2026
WordPress
Parameter Value
CVSS 9.1 (CRITICAL)
Affected Versions before 0.9.131
Type CWE-22 (Path Traversal), CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vendor WordPress
Public PoC No

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an unauthenticated request before using it to build a log file path, allowing an attacker holding a site to site transfer key to create a log file in any existing writable directory of the site, including the web root. The file name always carries a fixed suffix and the contents are always the WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131's own log header, so only the location of the file is attacker controlled.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products

unknown:wpvivid — backup, migration & staging