CRITICAL
WPvivid
CVE published 2026-08-16
CVE-2026-19725
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 is vulnerable to a log file path manipulation attack, allowing an unauthenticated attacker with a site-to-site transfer key to create log files in any writable directory, including the web root. This vulnerability enables potential log file manipulation, which could obscure malicious activity. The CVE record, published on 2026-08-16 [truncated]