CVE-2025-5961 | The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpvivid_upload_import_files' function in all versions up to, and including, 0.9.116. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. NOTE: Uploaded f
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpvivid_upload_import_files' function in all versions up to, and including, 0.9.116. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. NOTE: Uploaded files are only accessible on WordPress instances running on the NGINX web server as the existing .htaccess within the target file upload folder prevents access on Apache servers.
- 🔗 www.wordfence.com/threat-intel/vulnerabilities/id/d8ceb4a1-…
- 🔗 plugins.trac.wordpress.org/browser/wpvivid-backuprestore/trunk/inclu…
- 🔗 plugins.trac.wordpress.org/browser/wpvivid-backuprestore/trunk/inclu…
- 🔗 plugins.trac.wordpress.org/browser/wpvivid-backuprestore/trunk/inclu…
- 🔗 github.com/d0n601/CVE-2025-5961
- 🔗 ryankozak.com/posts/cve-2025-5961/
- 🔗 plugins.trac.wordpress.org/changeset/3320877/
```Code``` unterstützt. Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-23 | 2026-10-07 |
|---|---|---|
| ≥90 % | 491 | 344 |
| ≥50 % | 1475 | 1071 |
| ≥10 % | 0 | 3 |
| <10 % | 0 | 549 |
CVE-2025-5961 | The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpvivid_upload_import_files' function in all versions up to, and including, 0.9.116. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. NOTE: Uploaded f
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpvivid_upload_import_files' function in all versions up to, and including,
Noch keine Analyse zu CVE-2025-5961
Sei der Erste: Einschätzung, Betroffenheit, Workaround oder PoC — mit Antworten im Thread.