Segurium Research Advisories wpvivid-backuprestore

WPvivid Backup 0.9.132 and earlier: Path traversal

high Path traversal

WPvivid Backup 0.9.132 and earlier extracts backup archives without checking file paths. A crafted backup can write files outside the restore folder. Version 0.9.133 adds path containment checks and fixes SQL injection in the uploads cleaner.

Plugin
WPvivid Backup wpvivid-backuprestore
Affected versions
0.9.132 and earlier
Fixed in
0.9.133
Class
Path traversal
Severity
high Segurium Research assessment. No CVSS score published yet.
CVE
None assigned at the time of writing
Installs
900,000 active
Patch released
Sources
Read the teardown What the release changed, how the bug worked, and what to check on a site that ran the affected version.

Segurium Research writes these up from public source after the fix has shipped. We do not scan or probe third-party sites, and no teardown here carries a working exploit. Segurium itself is a WordPress malware scanner on the official directory at wordpress.org/plugins/segurium/.