WordPress Plugin Security Update Advisory (CVE-2026-1357)

WordPress Plugin Security Update Advisory (CVE-2026-1357)

Overview

 

We have released a security update to address a vulnerability in our WordPress plugin. Users of affected products are advised to update to the latest version.
 

 

Affected Products

 

CVE-2026-1357

 

WPvivid Backup & Migration Version: 0.9.123 and earlier

 

 

Resolved Vulnerabilities

 

Unauthenticated arbitrary file upload vulnerability in the WPvivid Backup & Migration plugin (CVE-2026-1357)

 

 

Vulnerability Patches

Vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2026-1357

 

WPvivid Backup & Migration Version: 0.9.124

 

 

References

 

[1] Migration, Backup, Staging <= 0.9.123 – Unauthenticated Arbitrary File Upload

Https:// http://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpvivid-backuprestore/migration-backup-staging-09123-unauthenticated-arbitrary-file-upload