---
id: CVE-2026-82194
title: >-
  The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does
  not validate a user supplied path before using it in a file deletion routine,
  allowing administrators to delete arbitrary files on the server, including
  files…
summary: >-
  The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does
  not validate a user supplied path before using it in a file deletion routine,
  allowing administrators to delete arbitrary files on the server, including
  files…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:L'
cwe:
  - CWE-73
published: '2026-09-04'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:15:18.627'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82194'
references:
  - url: 'https://wpscan.com/vulnerability/bb68f7ae-e380-4154-bd77-8511d8f949d3/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00335
epssPercentile: 0.2425
ingestedAt: '2026-09-08T20:10:03.163Z'
---

## Overview

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before using it in a file deletion routine, allowing administrators to delete arbitrary files on the server, including files outside the web root.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
