logo

WordPress Backup Plugin Vulnerability Exposes 800,000 Sites to Remote Code Execution Attacks

ID: a1640654-0c12-5c3e-8d33-82662af5b7c8

STIX ID: report--a1640654-0c12-5c3e-8d33-82662af5b7c8

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-02-12

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**Executive Summary:** A critical remote code execution vulnerability (CVE-2026-1357, CVSS 9.8) in the WPvivid Backup & Migration plugin (<= 0.9.123) allows unauthenticated attackers to upload and execute arbitrary PHP files due to improper RSA decryption error handling and insufficient filename sanitization, potentially impacting over 800,000 WordPress sites; the vendor released version 0.9.124 and Wordfence deployed firewall protections, and site owners are urged to update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.