WordPress Plugin Vulnerabilities

WPvivid Backup & Migration < 0.9.134 - Admin+ Arbitrary File Deletion via Path Traversal

Description

The plugin does not validate a user supplied path before using it in a file deletion routine, allowing administrators to delete arbitrary files on the server, including files outside the web root.

Proof of Concept

Affects Plugins

Fixed in 0.9.134

References

Classification

Type
FILE DELETION
CWE

Miscellaneous

Original Researcher
Meher Sudhakar Abbireddi
Submitter
Meher Sudhakar Abbireddi
Verified
Yes

Timeline

Publicly Published
2026-09-02 (about 2 days ago)
Added
2026-09-02 (about 1 day ago)
Last Updated
2026-09-02 (about 1 day ago)

Other