More than 900,000 WordPress websites are at risk from a serious flaw in the WPvivid Backup & Migration plugin. Is your website vulnerable too?
What is going on?
Security researchers have discovered a dangerous vulnerability in the WPvivid Backup & Migration plugin for WordPress. This plugin is used by more than 900,000 websites worldwide to create backups and migrate websites to another hosting environment.
The vulnerability — officially known as CVE-2026-1357 — has been given a severity score of 9.8 out of 10. That is virtually the maximum. An attacker without any access to your website can exploit this flaw to upload malicious files and gain full control of your website.
How exactly does the flaw work?
You don’t need to be a technical expert to understand the gist: the plugin has two flaws at the same time.
First, something goes wrong with the way the plugin encrypts keys and passwords. If a certain step in that process fails, the plugin doesn’t stop — it simply carries on with a predictable “fake key”. An attacker who knows this can use it to send fake files that the plugin treats as legitimate.
Second, the plugin does not properly check the file names of uploaded files. As a result, an attacker can place files outside the protected folder — including malicious PHP files that can be used to take over the website from the inside.
Are you vulnerable?
Not every user of the plugin runs the same risk. You are only critically vulnerable if you have enabled the “receive backup from another website” option. This is disabled by default, but many website administrators switch it on when they migrate a website from one hosting environment to another.
Moreover, an attacker only has a 24-hour window to exploit it, because the key needed for the attack expires after one day. Still, this is no reason to sit back: if you regularly use the plugin for migrations, that window is open again and again.
What should you do?
The advice is clear: update the WPvivid plugin to version 0.9.124 or later immediately.
This update was released on 28 January and contains three concrete improvements:
- The plugin now stops correctly when encryption fails, instead of carrying on with an insecure key.
- File names are now properly checked, so attackers can no longer place files outside the secure folder.
- Only permitted file types are now accepted (such as ZIP, GZ, TAR and SQL).
Timeline at a glance
| Date | What happened? |
|---|---|
| 12 January | Researcher Lucas Montes (NiRoX) discovers the flaw and reports it |
| 22 January | Security company Defiant informs the developer WPVividPlugins |
| 28 January | Version 0.9.124 containing the fix is released |
Conclusion
This is a serious vulnerability that you should not ignore. The risk of exploitation is real, especially if you use the plugin for website migrations. Check today which version of WPvivid you are using and update if necessary.
Do you need help securing your WordPress website, or would you like to know whether your website is vulnerable? Get in touch with Kyzoe — we will be happy to help.
Source: Defiant / Wordfence Security Research
Read also
Novamira: an AI agent working directly in your WordPress site
With Novamira, an AI agent such as Claude or Cursor works directly in WordPress. What it can do, what Pro adds, how…
Read moreFree WordPress plugin: age verification for your alcohol website (GDPR-compliant)
Do you sell wine, beer, whisky or other alcoholic drinks through your website? Then in Belgium (and most EU countries) you are…
Read moreKyzoe launches its first OTP plugin
We are launching a new WordPress plugin that generates One-Time Passwords (OTP). Minor news? Absolutely not — this is one of the…
Read more


