PatchSiren cyber security CVE debrief
CVE-2026-19725 WPvivid CVE debrief
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 is vulnerable to a log file path manipulation attack, allowing an unauthenticated attacker with a site-to-site transfer key to create log files in any writable directory, including the web root. This vulnerability enables potential log file manipulation, which could obscure malicious activity. The CVE record, published on 2026-08-16T06:16:52.487Z, has not been modified since then. The NVD entry is currently Deferred. Defenders should verify the WPvivid plugin version, restrict write access to log directories, and monitor for suspicious log file creation to mitigate potential risks. Limited information is available about the affected scope and vendor remediation. The vulnerability allows an attacker to create log files in any writable directory, including the web root, with a fixed suffix and containing the plugin's log header. It is crucial for affected parties to review compensating controls and ensure proper vulnerability management practices are in place.
- Vendor
- WPvivid
- Product
- Backup, Migration & Staging
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-16
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-16
- Advisory updated
- 2026-08-26
Who should care
WPvivid plugin users, WordPress site administrators, security teams monitoring for potential log file manipulation attacks, and operators of affected WordPress sites should be aware of this vulnerability. They should verify WPvivid plugin version, restrict write access to log directories, and monitor for suspicious log file creation to mitigate potential risks associated with this vulnerability. Additionally, reviewing compensating controls and ensuring proper vulnerability management practices are in place is crucial for affected parties.
Technical summary
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 is vulnerable to a log file path manipulation attack. An unauthenticated attacker with a site-to-site transfer key can create a log file in any existing writable directory of the site, including the web root. The file name has a fixed suffix and contains the plugin's log header. This vulnerability allows for potential log file manipulation and could be used to obscure malicious activity.
Defensive priority
Critical vulnerability in WPvivid plugin allows unauthenticated attackers to create log files in writable directories, including the web root.
Recommended defensive actions
- Inventory and verify WPvivid plugin version
- Restrict write access to log directories
- Monitor for suspicious log file creation
- Apply plugin update when available
- Review site transfer key usage
Evidence notes
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an unauthenticated request before using it to build a log file path. Limited information available about affected scope and vendor remediation. The vulnerability allows an attacker with a site-to-site transfer key to create log files in any writable directory, including the web root. Defenders should verify WPvivid plugin version, review site transfer key usage, and monitor for suspicious log file creation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-19725 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-19725
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-19725 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19725
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/999889f4-f8be-4b44-b665-1a94df8d050d/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.