Null Byte Nightmare: Critical WPvivid Backup Flaw (CVSS 9.8) Exposes 800K WordPress Sites
ID: 3f771b4f-19bc-57e2-bd97-ec530b2839f3
STIX ID: report--3f771b4f-19bc-57e2-bd97-ec530b2839f3
Feed Name: securityonline.info
A critical vulnerability (CVE-2026-1357, CVSS 9.8) in the WPvivid Backup WordPress plugin's site-to-site transfer feature allows unauthenticated attackers to bypass a broken decryption key check and upload arbitrary files (including PHP web shells), enabling remote code execution and full site takeover; roughly 800,000 installations could be impacted if the transfer feature is enabled. Wordfence observed active exploitation attempts and the plugin developers released version 0.9.124 to remediate the issue—sites should update immediately or disable the transfer feature.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
