Junglewise Threat Intelligence

CVE-2026-19722: WPvivid Backup, Migration & Staging path traversal in backup restore

CVE-2026-19722 · Severity: medium · CVSS 6.6 · Published 2026-08-30

Technologies: WPvivid Backup, Migration & Staging. Vendors: WPvivid.

Executive brief

WPvivid is a WordPress plugin for creating backups and migrating WordPress sites. The plugin fails to properly validate file paths when restoring from a backup archive, allowing site administrators to extract files to arbitrary locations on the server—including executable PHP files. An attacker with administrative access could use this to achieve remote code execution.

Technical details

The vulnerability is a path traversal (zip slip) flaw in the backup restoration logic. During extraction of files from a backup ZIP package, the plugin does not adequately validate the destination path, allowing specially crafted archive members with traversal sequences (../) to escape the intended restore directory. Two attack vectors were identified: (A) direct path traversal in archive member names, and (B) attacker control over the extraction root directory via a malicious wpvivid_package_info.json file. The flaw requires administrative privileges but no additional authentication or non-default configuration. An attacker can write arbitrary files (including PHP code) outside the restore directory, leading to code execution when WordPress auto-loads the malicious file. The vulnerability is fixed in version 0.9.133, which validates and rejects unsafe paths before extraction.

Affected products

  • WPvivid Backup, Migration & Staging before 0.9.133

Timeline

  • 2026-08-28: disclosed
  • 2026-08-28: patched: Version 0.9.133 released

References

Related threats