/Vulnerability Library

WPvivid Backup & Migration <= 0.9.123 - Arbitrary File Upload

CVE-2026-1357
Verified

Description

WPvivid Backup & Migration plugin for WordPress <= 0.9.123 contains an unauthenticated arbitrary file upload vulnerability caused by improper error handling in RSA decryption and lack of path sanitization, letting unauthenticated attackers upload arbitrary PHP files and achieve remote code execution via wpvivid_action=send_to_site parameter.

Severity

Critical

CVSS Score

9.8

Exploit Probability

35%

Affected Product

wpvivid-backuprestore

Published Date

February 13, 2026

Template Author

omarkurt

CVE-2026-1357.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-1357
CWE ID:
cwe-434

References

https://vulnerabletarget.com/VT-2026-1357https://github.com/LucasM0ntes/POC-CVE-2026-1357https://www.wordfence.com/threat-intel/vulnerabilities/id/e5af0317-ef46-4744-9752-74ce228b5f37https://nvd.nist.gov/vuln/detail/CVE-2026-1357

Remediation Steps

Update to the latest version of WPvivid Backup & Migration plugin.