THREAT OPS › Threat News › [NVD] CVE-2026-19722 — The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, allowing high privilege users such as administrators to write arbitrary files outside the intended restore dire
[NVD] CVE-2026-19722 — The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, allowing high privilege users such as administrators to write arbitrary files outside the intended restore dire
CVE-2026-19722 CVSS: None Published: 2026-08-30T07:17:20.880
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, allowing high privilege users such as administrators to write arbitrary files outside the intended restore directory, which can lead to code execution.
Indicators of compromise
- CVE-2026-19722cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-19722