SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82193

MEDIUM · CVSS 5.5 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The WPvivid Backup, Migration & Staging plugin for WordPress versions prior to 0.9.134 is vulnerable due to insufficient validation of user-supplied file names, enabling administrators to write files to arbitrary server locations and overwrite existing files. This flaw poses a significant risk of unauthorized file manipulation, which could lead to data loss or further exploitation of the server. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential security risks.

CVE
CVE-2026-82193
Severity
MEDIUM
CVSS
5.5
EPSS
0.26%
WordPress

Original NVD Description

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied file name before using it to build a write path, allowing administrators to write files of permitted types to arbitrary locations on the server and to overwrite existing files.