Critical RCE vulnerability in WPvivid Backup & Migration plugin
Summary
Hide ▲
Show ▼
A critical remote code execution (RCE) vulnerability (CVE-2026-1357) in the WPvivid Backup & Migration plugin for WordPress, installed on over 900,000 websites, allows unauthenticated attackers to upload arbitrary files. The flaw, rated 9.8 in severity, affects versions up to 0.9.123 and can lead to complete website takeover. The vulnerability stems from improper error handling in RSA decryption and lack of path sanitization, enabling directory traversal and malicious PHP file uploads. The issue is mitigated by a 24-hour exploitation window and the need for the 'receive backup from another site' option to be enabled. A patch (version 0.9.124) was released on January 28, 2026, addressing the flaw by improving error handling, filename sanitization, and restricting uploads to specific file types.
Timeline
-
12.02.2026 19:09 1 articles · 5h ago
Critical RCE vulnerability in WPvivid Backup & Migration plugin disclosed and patched
A critical remote code execution (RCE) vulnerability (CVE-2026-1357) in the WPvivid Backup & Migration plugin for WordPress, affecting versions up to 0.9.123, was disclosed and patched. The flaw, rated 9.8 in severity, allows unauthenticated attackers to upload arbitrary files and achieve remote code execution. The vulnerability was reported by researcher Lucas Montes (NiRoX) on January 12, 2026, and a patch (version 0.9.124) was released on January 28, 2026, addressing the issue by improving error handling, filename sanitization, and restricting uploads to specific file types.
Show sources
- WordPress plugin with 900k installs vulnerable to critical RCE flaw — www.bleepingcomputer.com — 12.02.2026 19:09
Information Snippets
-
The vulnerability is tracked as CVE-2026-1357 with a severity score of 9.8.
First reported: 12.02.2026 19:091 source, 1 articleShow sources
- WordPress plugin with 900k installs vulnerable to critical RCE flaw — www.bleepingcomputer.com — 12.02.2026 19:09
-
The flaw affects all versions of the WPvivid Backup & Migration plugin up to 0.9.123.
First reported: 12.02.2026 19:091 source, 1 articleShow sources
- WordPress plugin with 900k installs vulnerable to critical RCE flaw — www.bleepingcomputer.com — 12.02.2026 19:09
-
The vulnerability is caused by improper error handling in RSA decryption and lack of path sanitization.
First reported: 12.02.2026 19:091 source, 1 articleShow sources
- WordPress plugin with 900k installs vulnerable to critical RCE flaw — www.bleepingcomputer.com — 12.02.2026 19:09
-
Attackers can exploit the flaw to achieve remote code execution by uploading malicious PHP files.
First reported: 12.02.2026 19:091 source, 1 articleShow sources
- WordPress plugin with 900k installs vulnerable to critical RCE flaw — www.bleepingcomputer.com — 12.02.2026 19:09
-
The exploitation window is limited to 24 hours due to the validity of the generated key.
First reported: 12.02.2026 19:091 source, 1 articleShow sources
- WordPress plugin with 900k installs vulnerable to critical RCE flaw — www.bleepingcomputer.com — 12.02.2026 19:09
-
The 'receive backup from another site' option must be enabled for the vulnerability to be exploitable.
First reported: 12.02.2026 19:091 source, 1 articleShow sources
- WordPress plugin with 900k installs vulnerable to critical RCE flaw — www.bleepingcomputer.com — 12.02.2026 19:09
-
The vulnerability was reported by researcher Lucas Montes (NiRoX) on January 12, 2026.
First reported: 12.02.2026 19:091 source, 1 articleShow sources
- WordPress plugin with 900k installs vulnerable to critical RCE flaw — www.bleepingcomputer.com — 12.02.2026 19:09
-
The vendor, WPVividPlugins, was notified on January 22, 2026, and released a patch (version 0.9.124) on January 28, 2026.
First reported: 12.02.2026 19:091 source, 1 articleShow sources
- WordPress plugin with 900k installs vulnerable to critical RCE flaw — www.bleepingcomputer.com — 12.02.2026 19:09
-
The patch includes improved error handling, filename sanitization, and restricted uploads to specific file types.
First reported: 12.02.2026 19:091 source, 1 articleShow sources
- WordPress plugin with 900k installs vulnerable to critical RCE flaw — www.bleepingcomputer.com — 12.02.2026 19:09