Description
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in the delete_cancel_staging_site() function in all versions up to, and including, 0.9.128. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary folders on the server, which leads to a loss of data.
Problem types
CWE-73 External Control of File Name or Path
Product status
Any version
Timeline
| 2026-06-05: | Disclosed |
Credits
Chokri Hammedi
References
www.wordfence.com/...-3dc7-4f93-889c-d5e3530c7dba?source=cve
plugins.trac.wordpress.org/...ging/class-wpvivid-staging.php
plugins.trac.wordpress.org/...ging/class-wpvivid-staging.php
plugins.trac.wordpress.org/...ging/class-wpvivid-staging.php
wordpress.org/plugins/wpvivid-backuprestore/
plugins.trac.wordpress.org/...prestore&sfp_email=&sfph_mail=