WordPress plugin with 900k installs vulnerable to critical RCE flaw
ID: 51f78a8b-cf45-52b0-b86e-8bb572f10915
STIX ID: report--51f78a8b-cf45-52b0-b86e-8bb572f10915
Feed Name: Bleeping Computer
A critical RCE vulnerability (CVE-2026-1357, CVSS 9.8) in the WPvivid Backup & Migration plugin — present in versions up to 0.9.123 and installed on ~900k sites — allowed unauthenticated attackers to upload arbitrary files and perform directory traversal when the non-default “receive backup from another site” option was enabled; the flaw stemmed from improper RSA decryption error handling (resulting in a predictable AES key) and missing filename sanitization. Defiant validated a PoC and vendor WPVividPlugins released a patch in v0.9.124 that added a decryption failure check, filename sanitization, and upload type restrictions; administrators should update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
