SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82194

MEDIUM · CVSS 5.5 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The WPvivid Backup, Migration & Staging plugin for WordPress prior to version 0.9.134 is vulnerable due to inadequate validation of user-supplied paths in its file deletion process, which could enable administrators to delete arbitrary files on the server, including those outside the web root. This vulnerability poses a significant risk of data loss and server misconfiguration. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-82194
Severity
MEDIUM
CVSS
5.5
EPSS
0.20%
WordPress

Original NVD Description

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before using it in a file deletion routine, allowing administrators to delete arbitrary files on the server, including files outside the web root.