logo

WordPress Backup Plugin Vulnerability Exposes 800,000 Sites to Remote Code Execution Attacks

ID: d211f7fb-ef52-59de-83a8-9dd6e5d7f6f2

STIX ID: report--d211f7fb-ef52-59de-83a8-9dd6e5d7f6f2

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-02-12

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A critical unauthenticated arbitrary file upload vulnerability (CVE-2026-1357, CVSS 9.8) in WPvivid Backup & Migration (≤0.9.123) allows attackers to upload PHP files and achieve RCE via the receive-backup `send_to_site` endpoint due to RSA decryption error handling and unsanitized filenames; update to 0.9.124, disable receive-backup keys when not needed, rotate keys, and inspect the web root for unexpected PHP files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.