Executive brief
WPvivid is a popular WordPress plugin used for creating backups, migrating websites, and managing staging environments. The plugin fails to properly validate user-supplied file paths, allowing site administrators to delete arbitrary files on the server—including critical system files outside the web directory. This could lead to complete website destruction, loss of configuration files, or exposure of sensitive data.
Technical details
The vulnerability is a path traversal flaw in the file deletion routine of the WPvivid plugin. The vulnerable code appends user-supplied filenames directly to the isolate directory path (wp-content/wpvivid_uploads/Isolate) without sanitization, allowing traversal sequences (e.g., ../../) to escape the intended directory. Two AJAX handlers are affected: wpvivid_delete_selected_image (deletes individual files) and wpvivid_delete_all_image (deletes entire directories). Exploitation requires administrator privileges and a valid AJAX nonce, both of which are readily available to authenticated admins. An attacker with admin access can craft AJAX requests to delete files anywhere on the filesystem, including outside the web root. The vulnerability was patched in version 0.9.134.
Affected products
- WPvivid Backup, Migration & Staging before 0.9.134
Timeline
- 2026-09-02: disclosed
- 2026-09-04: patched: Fixed in version 0.9.134