PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-19725 WPvivid CVE debrief

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 is vulnerable to a log file path manipulation attack, allowing an unauthenticated attacker with a site-to-site transfer key to create log files in any writable directory, including the web root. This vulnerability enables potential log file manipulation, which could obscure malicious activity. The CVE record, published on 2026-08-16T06:16:52.487Z, has not been modified since then. The NVD entry is currently Deferred. Defenders should verify the WPvivid plugin version, restrict write access to log directories, and monitor for suspicious log file creation to mitigate potential risks. Limited information is available about the affected scope and vendor remediation. The vulnerability allows an attacker to create log files in any writable directory, including the web root, with a fixed suffix and containing the plugin's log header. It is crucial for affected parties to review compensating controls and ensure proper vulnerability management practices are in place.

Vendor
WPvivid
Product
Backup, Migration & Staging
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-16
Original CVE updated
2026-08-26
Advisory published
2026-08-16
Advisory updated
2026-08-26

Who should care

WPvivid plugin users, WordPress site administrators, security teams monitoring for potential log file manipulation attacks, and operators of affected WordPress sites should be aware of this vulnerability. They should verify WPvivid plugin version, restrict write access to log directories, and monitor for suspicious log file creation to mitigate potential risks associated with this vulnerability. Additionally, reviewing compensating controls and ensuring proper vulnerability management practices are in place is crucial for affected parties.

Technical summary

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 is vulnerable to a log file path manipulation attack. An unauthenticated attacker with a site-to-site transfer key can create a log file in any existing writable directory of the site, including the web root. The file name has a fixed suffix and contains the plugin's log header. This vulnerability allows for potential log file manipulation and could be used to obscure malicious activity.

Defensive priority

Critical vulnerability in WPvivid plugin allows unauthenticated attackers to create log files in writable directories, including the web root.

Recommended defensive actions

  • Inventory and verify WPvivid plugin version
  • Restrict write access to log directories
  • Monitor for suspicious log file creation
  • Apply plugin update when available
  • Review site transfer key usage

Evidence notes

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an unauthenticated request before using it to build a log file path. Limited information available about affected scope and vendor remediation. The vulnerability allows an attacker with a site-to-site transfer key to create log files in any writable directory, including the web root. Defenders should verify WPvivid plugin version, review site transfer key usage, and monitor for suspicious log file creation.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-19725 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-19725

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-19725 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19725

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.