在 WPvivid — Backup, Migration & Staging WordPress 插件(版本低于 0.9.131)中,未对来自未认证请求的值进行 sanitise(净化/过滤)处理就直接用于构建日志文件路径。这使得持有站点对站点传输密钥的攻击者能够在网站任意可写目录(包括 Web 根目录)中创建日志文件。 文件名始终带有固定的后缀,文件内容始终为该插件自身的前置日志头信息,因此攻击者仅能控制文件的存放位置。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | WPvivid — Backup, Migration & Staging | < 0.9.131 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | WPvivid — Backup, Migration & Staging | 0 ~ 0.9.131 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-19726 | Visualizer < 4.0.7 - Contributor+ Cross-User Chart Configuration Disclosure | |
| CVE-2026-19728 | Extra Product Options Builder for WooCommerce < 1.2.176 - Unauthenticated Customer File Di | |
| CVE-2026-18653 | WP Directory Kit < 1.5.7 - Admin+ SQL Injection via section Parameter | |
| CVE-2026-19712 | Masteriyo LMS < 2.3.3 - Instructor+ Stored XSS via Quiz Description | |
| CVE-2026-19613 | ECS < 4.3.10 - Contributor+ Arbitrary Post Meta Disclosure via Dynamic Repeater ACF Source | |
| CVE-2026-19717 | CatFolders Document Gallery < 2.0.7 - Unauthenticated Attachment Disclosure via REST API | |
| CVE-2026-19714 | Simple JWT Login < 3.6.8 - Unauthenticated Account Takeover via Missing Google id_token Au | |
| CVE-2026-19711 | Premium Packages – Sell Digital Products Securely < 7.0.7 - Subscriber+ Arbitrary Amount W | |
| CVE-2026-15384 | Manual Image Crop < 1.15 - Subscriber+ Arbitrary Attachment Image Overwrite via IDOR | |
| CVE-2026-13712 | Divi 5.0 - 5.8.1 - Contributor+ Stored XSS via Social Media Follow Skype URL | |
| CVE-2026-17533 | All-in-One WP Migration and Backup < 7.108 - Multisite Subsite Admin+ Network-Wide PHP Cod |
No comments yet