Nearly a Million WordPress Websites Could Be at Risk Due to This Serious Plugin Security Flaw



  • WPvivid Backup & Migration plugin is vulnerable to critical RCE flaw CVE-2026-1357
  • The exploit requires the “receive backup from another site” option enabled, with a 24-hour attack window
  • Patch released in version 0.9.123 (January 28); Users are urged to update immediately.

WPvivid Backup & Migration, a WordPress plugin with nearly a million installations, is vulnerable to a critical flaw that allows threat actors to execute malicious code remotely.

Although it sounds sinister, the bug has some limitations that make it a bit difficult to exploit.



Leave a Comment

Your email address will not be published. Required fields are marked *