THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-19722 — The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, allowing high privilege users such as administrators to write arbitrary files outside the intended restore dire

[NVD] CVE-2026-19722 — The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, allowing high privilege users such as administrators to write arbitrary files outside the intended restore dire

mednvdPublished 2026-08-30

CVE-2026-19722 CVSS: None Published: 2026-08-30T07:17:20.880

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, allowing high privilege users such as administrators to write arbitrary files outside the intended restore directory, which can lead to code execution.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-19722