Executive brief
WPvivid Backup & Migration is a WordPress plugin used to create website backups, migrate sites to new domains, and set up staging environments. A security flaw in the plugin allows an authorized administrator to delete folders on the web server that they should not have access to. This could lead to the accidental or intentional loss of critical website data or system files.
Technical details
The WPvivid Backup & Migration plugin for WordPress (versions up to 0.9.128) contains an arbitrary directory deletion vulnerability. The flaw exists within the delete_cancel_staging_site() function due to insufficient validation of file paths provided by the user. An authenticated attacker with Administrator-level privileges can exploit this to delete arbitrary folders on the server. While administrators typically have broad access, this vulnerability allows for the deletion of directories outside of the intended staging scope, potentially leading to data loss or service disruption. The issue was addressed in version 0.9.129.
Affected products
- wpvividplugins WPvivid Backup & Migration up to, and including, 0.9.128
Timeline
- 2026-06-06: disclosed: Vulnerability published via NVD and Wordfence
- 2026-06-06: patched: Fixed in version 0.9.129
References
- https://plugins.trac.wordpress.org/browser/wpvivid-backuprestore/tags/0.9.120/includes/staging/class-wpvivid-staging.php
- https://plugins.trac.wordpress.org/browser/wpvivid-backuprestore/tags/0.9.120/includes/staging/class-wpvivid-staging.php
- https://plugins.trac.wordpress.org/browser/wpvivid-backuprestore/tags/0.9.120/includes/staging/class-wpvivid-staging.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3556022%40wpvivid-backuprestore&new=3556022%40wpvivid-backuprestore&sfp_email=&sfph_mail=
- https://wordpress.org/plugins/wpvivid-backuprestore/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/2f5962e5-3dc7-4f93-889c-d5e3530c7dba?source=cve