logo

WordPress plugin with 900k installs vulnerable to critical RCE flaw

ID: 51f78a8b-cf45-52b0-b86e-8bb572f10915

STIX ID: report--51f78a8b-cf45-52b0-b86e-8bb572f10915

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-02-12

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A critical RCE vulnerability (CVE-2026-1357, CVSS 9.8) in the WPvivid Backup & Migration plugin — present in versions up to 0.9.123 and installed on ~900k sites — allowed unauthenticated attackers to upload arbitrary files and perform directory traversal when the non-default “receive backup from another site” option was enabled; the flaw stemmed from improper RSA decryption error handling (resulting in a predictable AES key) and missing filename sanitization. Defiant validated a PoC and vendor WPVividPlugins released a patch in v0.9.124 that added a decryption failure check, filename sanitization, and upload type restrictions; administrators should update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.