CVE-2026-19722: WPvivid Backup & Migration < 0.9.133 - Admin+ Arbitrary File Write via Zip Slip in Backup Restore
Published Aug 30, 2026
·Updated
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, allowing high privilege users such as administrators to write arbitrary files outside the intended restore directory, which can lead to code execution.
Affected Software
1 affected component
WPvivid WPvivid — Backup, Migration & Staging<0.9.133
Event History
Aug 30, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:17 AM
Description
Frequently Asked Questions
1
Who can exploit this issue?
Exploitation requires a high-privilege WordPress user, such as an administrator, who can perform a backup restoration using the affected plugin.
2
What does an attacker need to do to trigger the vulnerability?
They need to restore a backup package containing crafted archive paths. The plugin can extract those files outside the intended restoration directory.
3
What is the recommended remediation?
Update WPvivid Backup & Migration to version 0.9.133 or later. Versions earlier than 0.9.133 are affected.