PatchSiren

WPvivid CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL WPvivid CVE published 2026-08-16

CVE-2026-19725

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 is vulnerable to a log file path manipulation attack, allowing an unauthenticated attacker with a site-to-site transfer key to create log files in any writable directory, including the web root. This vulnerability enables potential log file manipulation, which could obscure malicious activity. The CVE record, published on 2026-08-16 [truncated]