CVE-2026-82194: WPvivid Backup & Migration < 0.9.134 - Admin+ Arbitrary File Deletion via Path Traversal
Published Sep 4, 2026
·Updated
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before using it in a file deletion routine, allowing administrators to delete arbitrary files on the server, including files outside the web root.
Affected Software
1 affected component
WPvivid WPvivid — Backup, Migration & Staging WordPress plugin<0.9.134
Event History
Sep 4, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Can an unauthenticated or low-privileged WordPress user exploit this issue?
The issue is described as requiring administrator-level access. The provided information does not indicate that unauthenticated or lower-privileged users can trigger it.
2
Which plugin versions are affected?
WPvivid Backup & Migration plugin versions before 0.9.134 are affected. Version 0.9.134 is the first version not identified as vulnerable in the provided data.