Executive brief
The WPvivid Backup for MainWP plugin for WordPress, which helps manage backups across multiple sites, contains a security flaw in its administrative settings. This vulnerability allows an authorized administrator to save malicious scripts into the website's configuration. These scripts would then execute in the browsers of other users who visit the affected settings pages, potentially leading to unauthorized actions or data access within the management console.
Technical details
The WPvivid Backup for MainWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping within the administrative settings. An authenticated attacker with administrator-level permissions can inject arbitrary web scripts into the database. These scripts execute when a user accesses the modified settings page. This vulnerability specifically impacts WordPress multi-site installations or environments where the 'unfiltered_html' capability has been disabled for administrators. The issue is present in all versions up to and including 0.9.33.
Affected products
- WPvivid Team WPvivid Backup for MainWP up to, and including, 0.9.33
Timeline
- 2026-07-10: disclosed
- 2026-07-10: advisory