---
id: CVE-2026-19722
title: >-
  The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does
  not validate the destination of files extracted from a backup package during
  restoration, allowing high privilege users such as administrators to write
  arbitr…
summary: >-
  The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does
  not validate the destination of files extracted from a backup package during
  restoration, allowing high privilege users such as administrators to write
  arbitr…
severity: none
published: '2026-08-30'
updated: '2026-08-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19722'
references:
  - url: 'https://wpscan.com/vulnerability/a61974fc-d9d6-4aee-a624-fc0a6e7b940b/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00258
epssPercentile: 0.15571
ingestedAt: '2026-08-30T15:54:21.839Z'
---

## Overview

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, allowing high privilege users such as administrators to write arbitrary files outside the intended restore directory, which can lead to code execution.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
