CVE-2026-19722

Published: Ago 30, 2026 Last Modified: Ago 30, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, allowing high privilege users such as administrators to write arbitrary files outside the intended restore directory, which can lead to code execution.

https://wpscan.com/vulnerability/a61974fc-d9d6-4aee-a624-fc0a6e7b940b/