CVE-2026-19722EPSS p15.9%

CVE-2026-19722CVE-2026-19722

Description

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, allowing high privilege users such as administrators to write arbitrary files outside the intended restore directory, which can lead to code execution.

Scoring

CVSS 6.6 ()
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
EPSS0.26% probability of exploitation · percentile 15.9% · 2026-10-05T12:00:23Z
Last modified2026-09-03
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.