WordPress Plugin Vulnerabilities
WPvivid Backup & Migration < 0.9.133 - Admin+ Arbitrary File Write via Zip Slip in Backup Restore
Description
The plugin does not validate the destination of files extracted from a backup package during restoration, allowing high privilege users such as administrators to write arbitrary files outside the intended restore directory, which can lead to code execution.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
TRAVERSAL
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Nir Yehoshua
Submitter
Nir Yehoshua
Submitter website
Submitter twitter
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-08-28 (about 2 days ago)
Added
2026-08-28 (about 1 day ago)
Last Updated
2026-08-28 (about 1 day ago)