CVE-2025-5961: Migration, Backup, Staging – WPvivid Backup & Migration <= 0.9.116 - Authenticated (Administrator+) Arbitrary File Upload
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpvividuploadimportfiles' function in all versions up to, and including, 0.9.116. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. NOTE: Uploaded files are only accessible on WordPress instances running on the NGINX web server as the existing .htaccess within the target file upload folder prevents access on Apache servers.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5961?
CVE-2025-5961 is a high-severity vulnerability that allows arbitrary file uploads due to insufficient file type validation.
How do I fix CVE-2025-5961?
To fix CVE-2025-5961, update the WPvivid Backup & Migration plugin to version 0.9.117 or later.
Who is affected by CVE-2025-5961?
All users of the WPvivid Backup & Migration plugin for WordPress using versions up to and including 0.9.116 are affected by CVE-2025-5961.
What is the impact of CVE-2025-5961?
CVE-2025-5961 can lead to unauthorized access and potential compromise of the WordPress site due to arbitrary file upload capabilities.
Is there a workaround for CVE-2025-5961?
A temporary workaround for CVE-2025-5961 includes disabling the WPvivid Backup & Migration plugin until an update can be applied.