WPvivid — Backup, Migration & Staging WordPress 插件在 0.9.133 版本之前,在恢复备份包时未对解包文件的目的地进行验证,导致高权限用户(如管理员)可以将任意文件写入到预设的恢复目录之外,从而可能导致代码执行漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | WPvivid — Backup, Migration & Staging | 0 ~ 0.9.133 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81660 | Groundhogg < 4.5.13 - Unauthenticated Stored XSS via Web Form Dropdown/Radio Field | |
| CVE-2026-81766 | Really Simple Security < 9.8.0 - Multisite Subsite Admin+ Arbitrary Plugin Installation vi | |
| CVE-2026-78364 | MW WP Form < 5.1.6 - Editor+ Stored XSS via Inquiry Data List | |
| CVE-2026-76585 | Customer Reviews for WooCommerce < 5.118.0 - Unauthenticated Stored XSS via 'comment' Para | |
| CVE-2026-14835 | SOGO Add Script to Individual Pages Header Footer <= 3.9 - Contributor+ Stored XSS via Pos | |
| CVE-2026-14307 | Geotargeting WP < 3.5.6.2 - Reflected XSS |
No comments yet