PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-15283 wpvividplugins CVE debrief

The WPvivid Backup for MainWP plugin for WordPress has a Stored Cross-Site Scripting vulnerability due to insufficient input sanitization and output escaping in admin settings. Authenticated attackers with administrator-level permissions can inject web scripts, affecting multi-site installations and those with unfiltered_html disabled. This vulnerability has a CVSS score of 4.4, indicating a Medium severity level. Administrators should verify and update to the latest version to prevent potential XSS attacks. The vulnerability only affects multi-site installations and installations where unfiltered_html has been disabled.

Vendor
wpvividplugins
Product
WPvivid Backup for MainWP
CVSS
MEDIUM 4.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-10
Original CVE updated
2026-07-10
Advisory published
2026-07-10
Advisory updated
2026-07-10

Who should care

Administrators of WordPress multi-site installations or those with unfiltered_html disabled, using WPvivid Backup for MainWP plugin versions up to 0.9.33, should verify and update to the latest version to prevent potential XSS attacks. This includes reviewing and restricting administrator-level permissions, monitoring for suspicious admin activity, and implementing additional security measures for multi-site installations.

Technical summary

The WPvivid Backup for MainWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 0.9.33. This is due to insufficient input sanitization and output escaping. An attacker with administrator-level permissions and above can inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability only affects multi-site installations and installations where unfiltered_html has been disabled. The CVSS score for this vulnerability is 4.4, indicating a Medium severity level.

Defensive priority

High priority for administrators of affected WordPress installations to verify and apply updates.

Recommended defensive actions

  • Verify and update WPvivid Backup for MainWP plugin to the latest version
  • Review and restrict administrator-level permissions
  • Monitor for suspicious admin activity
  • Implement additional security measures for multi-site installations
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record was published on 2026-07-10T05:16:30.943Z and was last modified on 2026-07-10T15:43:30.330Z. The NVD entry is currently Deferred. This information is based on the supplied source corpus and may not reflect the current status. Defenders should verify the affected scope and vendor guidance through official channels.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-15283 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-15283

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-15283 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-15283

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.