[CVE-2026-19722] The WPvivid — Backup, Migration & Staging WordPress plugin b

CVE-2026-19722 | CVSS: N/A

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, allowing high privilege users such as administrators to write arbitrary files outside the intended restore directory, which can lead to code execution.

参考链接:
https://wpscan.com/vulnerability/a61974fc-d9d6-4aee-a624-fc0a6e7b940b/

📌 数据来源: NVD 官方

⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。
滚动至顶部