WordPress Backup Plugin Vulnerability Exposes 800,000 Sites to Remote Code Execution Attacks
ID: d211f7fb-ef52-59de-83a8-9dd6e5d7f6f2
STIX ID: report--d211f7fb-ef52-59de-83a8-9dd6e5d7f6f2
Feed Name: cybersecurityNews.com
Threat Score
A critical unauthenticated arbitrary file upload vulnerability (CVE-2026-1357, CVSS 9.8) in WPvivid Backup & Migration (≤0.9.123) allows attackers to upload PHP files and achieve RCE via the receive-backup `send_to_site` endpoint due to RSA decryption error handling and unsanitized filenames; update to 0.9.124, disable receive-backup keys when not needed, rotate keys, and inspect the web root for unexpected PHP files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
