← Back to browse · API

CVE-2025-5961

Severity
HIGH
CVSS
7.2
EPSS
0.48659
Risk score
45.83
CISA KEV
No
PoC
No
Published
2025-07-03
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2025-19880, GHSA-49M8-X93V-846R
Products
wpvividplugins:WPvivid — Backup, Migration & Staging 0 ≤0.9.116
Sources
euvd EUVD-2025-19880

Description

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpvivid_upload_import_files' function in all versions up to, and including, 0.9.116. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. NOTE: Uploaded files are only accessible on WordPress instances running on the NGINX web server as the existing .htaccess within the target file upload folder prevents access on Apache servers.

References