WPvivid transfer logging permits authenticated path traversal
WPvivid Backup and Migration before 0.9.131 accepts attacker-controlled path data during a site-to-site transfer and uses it when creating a transfer log. A remote requester must possess a valid site-to-site transfer key, but can then traverse into any existing directory writable by PHP and create the plugin's fixed-name log file there. Only the location is controlled: the filename suffix and log header are fixed, and.
- Component
- WPvivid — Backup, Migration & Staging
- Plugin slug
wpvivid-backuprestore- Affected
- < 0.9.131
- Safe version
0.9.131- Published
- Aug 16, 2026
This CVE was published Aug 16, 2026 and is one of 15 known issues for this plugin.
Update, patch or deactivate.
Update to 0.9.131 or later, rotate site-to-site transfer keys, remove stale transfer relationships, and inspect writable directories for unexpected WPvivid log files.
A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.
Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.
Technical description
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an unauthenticated request before using it to build a log file path, allowing an attacker holding a site to site transfer key to create a log file in any existing writable directory of the site, including the web root. The file name always carries a fixed suffix and the contents are always the WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131's own log header, so only the location of the file is attacker controlled.
CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N