Critical WPvivid Backup Plugin Flaw Exposes 800,000+ WordPress Sites to Remote Code Execution
A serious security vulnerability has been discovered in the WPvivid Backup & Migration plugin , placing more than 800,000 WordPress websites at potential risk of remote code execution. The issue was identified through the Wordfence Bug Bounty Program and affects plugin versions up to 0.9.123. It has been assigned a critical CVSS score of 9.8 under CVE-2026-1357 . What’s the Risk? The vulnerability allows unauthenticated attackers to upload malicious files to affected websites. In certain configurations, this can result in complete site compromise. Once a malicious file such as a web shell is uploaded and executed, attackers can gain full control over the WordPress environment. The exploit is triggered using the wpvivid_action=send_to_site parameter, which is connected to the plugin’s backup transfer functionali...