WordPress Plugin Security Update Advisory (CVE-2026-1357)
Overview
We have released a security update to address a vulnerability in our WordPress plugin. Users of affected products are advised to update to the latest version.
Affected Products
CVE-2026-1357
WPvivid Backup & Migration Version: 0.9.123 and earlier
Resolved Vulnerabilities
Unauthenticated arbitrary file upload vulnerability in the WPvivid Backup & Migration plugin (CVE-2026-1357)
Vulnerability Patches
Vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2026-1357
WPvivid Backup & Migration Version: 0.9.124
References
[1] Migration, Backup, Staging <= 0.9.123 – Unauthenticated Arbitrary File Upload
Https:// http://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpvivid-backuprestore/migration-backup-staging-09123-unauthenticated-arbitrary-file-upload