Exploitation observed; activity peaked at 7 mentions and remains active
Immediate actions
Patch affected systems immediately
Assume compromise if assets are exposed
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: Immediate (within 24h)
NVD description
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions up to and including 0.9.123. This is due to improper error handling in the RSA decryption process combined with a lack of path sanitization when writing uploaded files. When the plugin fails to decrypt a session key using openssl_private_decrypt(), it does not terminate execution and instead passes the boolean false value to the phpseclib library's AES cipher initialization. The library treats this false value as a string of null bytes, allowing an attacker to encrypt a malicious payload using a predictable null-byte key. Additionally, the plugin accepts filenames from the decrypted payload without sanitization, enabling directory traversal to escape the protected backup directory. This makes it possible for unauthenticated attackers to upload arbitrary PHP files to publicly accessible directories and achieve Remote Code Execution via the wpvivid_action=send_to_site parameter.
💥 Dropped my PoC for CVE-2026-1357 (9.8) — WPvivid Backup & Migration (900k+ installs)
Unauth → Arbitrary file upload → RCE 🚨
Root cause: cryptographic fail-open + path traversal combo.
Full PoC and write up👇
https://github.com/LucasM0ntes/POC-CVE-2026-1357
Post summary
The tweet announces a proof‑of‑concept for CVE‑2026‑1357, demonstrating unauthenticated arbitrary file upload leading to remote code execution on the WPvivid plugin, and links to the GitHub repository with the PoC.
A new unauthenticated takeover vulnerability (CVE‑2026‑1357) in the WPvivid backup plugin has been disclosed, affecting more than 70,000 sites; a patch has been issued but many users have yet to update.
🚨 CRITICAL WORDPRESS VUNERABIITY 🚨
Found a pre-auth RCE via a 2-bug exploit chain in WPvivid Backup & Migration (700K+ active installs).
💥 CVSS: 9.8 (CRITICAL)
🆔 CVE-2026-1357
🙏 Thanks to @wordfence
💰 $2,145 bounty paid
More to come 👀🔥 and update NOW!! https://t.co/PAgsUiBLnD
Post summary
The tweet announces a critical WordPress vulnerability (CVE‑2026‑1357) with a pre‑authentication RCE and a high CVSS score, noting a bounty payout but providing no PoC, exploit code, or patch information.
CVE-2026-1357: WordPress Plugin RCE Exposes Sites to Full Takeover
https://securityboulevard.com/2026/02/cve-2026-1357-wordpress-plugin-rce-exposes-sites-to-full-takeover/
『(直訳)WordPressプラグイン「WPvivid Backup & Migration」に重大な脆弱性が発見され、認証されていない攻撃者が公開されているウェブサイトに任意のPHPファイルをアップロード・実行できる可能性があります』
Post summary
A critical RCE vulnerability in the WordPress plugin WPvivid Backup & Migration permits unauthenticated attackers to upload and run arbitrary PHP, potentially leading to full site takeover.
New PCPJack worm targets cloud infrastructure, stealing credentials from Docker/Kubernetes/Redis while actively removing TeamPCP infections. Exploits 5 recent CVEs including CVE-2025-29927 and CVE-2026-1357 for initial access.
#DFIR_Radar https://t.co/4pMlgIN6MQ
Post summary
The post reports that the PCPJack worm actively exploits CVE-2025-29927 and CVE-2026-1357 for initial access in cloud environments.
🚨 CVE-2026-1357 - critical 🚨
WPvivid Backup & Migration <= 0.9.123 - Arbitrary File Upload
> WPvivid Backup & Migration plugin for WordPress <= 0.9.123 contains an unauthenticate...
👾 https://cloud.projectdiscovery.io/library/CVE-2026-1357
@pdnuclei#NucleiTemplates#cve
Post summary
The post announces CVE-2026-1357, an arbitrary file upload flaw in WPvivid Backup & Migration plugin up to version 0.9.123, without providing exploits, patches, or evidence of active attacks.
Directoratul Național de Securitate Cibernetică@DNSC_RO·
Disclosure
🚨 ALERTĂ: Vulnerabilitate critică în plugin-ul Wordpress WPvivid Backup & Migration (CVE-2026-1357)
🔗 Mai multe detalii, în alerta de pe site-ul DNSC:
👉 https://www.dnsc.ro/citeste/alerta-vulnerabilitate-critica-in-plugin-ul-wordpress-wpvivid-backup-migration
#DNSC#CyberSecurity#CyberAlert#Vulnerability#CVE#WordPress https://t.co/vB6ONL4wFG
Post summary
The tweet announces a critical vulnerability (CVE-2026-1357) in the WPvivid WordPress plugin and directs readers to a DNSC alert for further details.
🚨 Critical WPvivid Backup flaw (CVE-2026-1357) exposes 800K+ WordPress sites to unauth RCE
WPvivid Backup & Migration (≤ 0.9.123) is vulnerable to an unauthenticated arbitrary file upload that can be weaponized for remote code execution/site takeover when untrusted backup-transfer paths are reachable; update to 0.9.124+ immediately and audit for unexpected uploads/webshells. Public details cite RSA decryption error-handling + path sanitization gaps enabling attackers to write files to public directories.
🎯 Target: Global/WordPress (Web Hosting & SMEs)
#️⃣ Category: #Vulnerability#BlueTeam#CyberIntel
🔗 URL: https://cyberpress.org/wordpress-backup-plugin-exploit/
Post summary
The post announces a critical unauthenticated RCE flaw in WPvivid Backup (CVE-2026-1357), provides technical details of the vulnerability, links to additional information, and urges an immediate upgrade to version 0.9.124+ to mitigate the risk.
New critical 0‑day in the wild: CVE‑2026‑1357 – WPvivid Backup & Migration ≤ 0.9.123
PoC: https://github.com/Nxploited/CVE-2026-1357
Telegram: https://t.me/KNxploited/
#WordPress#CVE2026#BugBounty#RCE#WPvivid#Infosec#CyberSecurity#Exploit#Pentest
Post summary
The post announces that CVE‑2026‑1357, a critical 0‑day affecting WPvivid Backup & Migration, is being used in the wild, with a PoC link provided for exploitation.
🚨 New Blog Post: CVE-2026-1357 (CVSS 9.8) — Unauthenticated RCE in WPvivid Backup Plugin
A cryptographic fail-open + path traversal chain = full remote code execution without credentials.
In our latest technical breakdown, we dissect how WPvivid Backup & Migration (≤ 0.9.123) can be exploited to write arbitrary files and drop a web shell, and how version 0.9.124 fixes it.
If you run WordPress or monitor KEVs at scale, this one matters.
👉 Read the full analysis and PoC walkthrough on our blog : https://blog.ostorlab.co/cve-2026-1357-unauthenticated-rce-wpvivid.html
#CVE20261357#WordPressSecurity
Post summary
The article announces a high‑severity RCE in WPvivid Backup, provides a PoC walkthrough, technical details, and notes that the next plugin version resolves the flaw.
CVE-2026-1357
Critical #RCE in WPvivid Backup & Migration plugin affects versions ≤ 0.9.123 and has a CVSS 9.8 severity score.
Unauthenticated attackers can exploit improper RSA error handling and unsanitized file paths to upload arbitrary PHP files and execute remote code
⚠️ Why it matters:
Backup/migration workflows now create an unexpected entry point for full site takeover on many WordPress sites.
🛠 Fix:
Update the plugin to 0.9.124 or later immediately and review any unexpected files if the vulnerable feature was used.
#WordPressSecurity#CVE#WebSecurity#RemoteCodeExecution#CyberThreats#Malware#CyberSecurity
Post summary
The post highlights a critical RCE in WPvivid Backup & Migration plugin (CVE‑2026‑1357) with a CVSS 9.8 score and advises updating to 0.9.124 or later, but does not report active exploitation or provide an exploit tool.
The post announces that CVE‑2026‑1357 in the WPvivid backup plugin has been fixed, detailing the RCE mechanism via RSA decryption and directory traversal vulnerabilities.
🚨 Vulnerabilidad crítica en WPvivid Backup & Migration afecta a 900.000 sitios de WordPress
https://cibered.com/ciberseguridad/noticias/wpvivid-backup-migration-rce-cve-2026-1357/
#WordPress#Vulnerabilidades#Ciberseguridad#Cibered
Post summary
A critical remote code execution vulnerability (CVE‑2026‑1357) in WPvivid Backup & Migration affecting up to 900,000 WordPress sites has been reported, with no evidence of PoC, active exploitation, or patch details provided.
#CVE-2026-1357 — Critical #WordPress Plugin Vulnerability
The WPvivid Backup & Migration plugin (≤ 0.9.123) allows unauthenticated arbitrary file upload due to improper RSA error handling and missing path sanitization.
Why this matters:
Attackers can upload a malicious PHP file and execute it on the server — leading to Remote Code Execution (RCE) and full site takeover.
What to do now:
• Update to the latest patched version immediately
• Audit recent uploads and admin users
• Scan for unexpected PHP files/backdoors
How to reduce future risk:
• Keep plugins updated promptly
• Remove unused plugins
• Restrict file upload capabilities
• Monitor for anomalous file changes
Security gaps in upload logic can escalate quickly — patching speed is critical.
#WordPressSecurity#CyberThreats#Malware#CVE
Post summary
The tweet announces a critical file‑upload vulnerability in WPvivid Backup & Migration (CVE‑2026‑1357), warns of remote code execution risks, and urges immediate patching and security checks.
برای یکی از معروفترین پلاگین های این CMS ، یعنی WPvivid Backup آسیب پذیری با کد شناسایی CVE-2026-1357 از نوع RCE منتشر شده است ، این آسیب پذیری به هکرها اجازه upload فایل PHP و اجرا کردن آن را می دهد. https://t.co/eHDnlIS2WG
Post summary
A newly disclosed RCE vulnerability (CVE‑2026‑1357) in the WPvivid Backup plugin permits attackers to upload and execute PHP files.
🚨 WordPress Backup Plugin Vulnerability Exposes 900K Sites
A critical vulnerability in the WPvivid Backup & Migration plugin for WordPress can be exploited to achieve remote code execution by uploading arbitrary files without authentication.
Tracked as CVE-2026-1357, the flaw impacts all plugin versions up to and including 0.9.123, with exposure requiring the non-default "receive backup from another site" option to be enabled and website takeover described as the end result.
🔗Details → https://hackeraffairs.com/wordpress-backup-plugin-vulnerability-exposes-900k-sites/
Post summary
The post announces CVE-2026-1357 for the WPvivid Backup & Migration plugin, detailing how it enables remote code execution through unauthenticated file uploads and the specific conditions that trigger it.
Today's Top Cybersecurity News – February 13, 2026
1. Critical WPvivid Backup Flaw (CVSS 9.8) Exposes 800K WordPress Sites
A critical vulnerability (CVE-2026-1357) in the WPvivid Backup plugin affects over 800,000 WordPress sites, potentially exposing sensitive backup data. This flaw poses a significant risk of data compromise and site integrity loss if exploited.
Sources: Bleepingcomputer, Cvefeed, Darkreading, Feedburner, Gbhackers, Infosecurity-Magazine, Intel471, Malwarebytes, Mandiant, Proofpoint, Securityweek, Therecord
https://securityonline.info/null-byte-nightmare-critical-wpvivid-backup-flaw-cvss-9-8-exposes-800k-wordpress-sites/
2. Critical SandboxJS Vulnerability (CVE-2026-25881) Enables Host Takeover
A critical flaw in SandboxJS allows attackers to escape the sandbox environment and execute malicious code on the host system. This vulnerability poses a severe risk to applications relying on SandboxJS for secure JavaScript execution.
Sources: Cvefeed, Microsoft
https://securityonline.info/sandbox-breakout-critical-sandboxjs-flaw-cve-2026-25881-allows-host-takeover/
3. Multiple High and Critical Vulnerabilities Including Authentication Bypass, Buffer Overflows, and Path Traversal
A series of critical and high-severity vulnerabilities have been disclosed affecting various software products including PRO-7070, OwnCloud, SpotAuditor, and others. These vulnerabilities enable attackers to bypass authentication, execute arbitrary code via buffer overflows and stack overflows, perform path traversal to access sensitive files, and disclose usernames, posing significant risks to affected systems. Immediate patching and mitigation are recommended to prevent unauthorized access and potential system compromise.
Sources: Cvefeed
https://cvefeed.io/vuln/detail/CVE-2019-25335
4. Multiple Critical Vulnerabilities in CIPPlanner CIPAce Allow Privilege Escalation and Arbitrary File Access
CIPPlanner CIPAce versions before 9.17 contain multiple severe vulnerabilities including account privilege escalation, unauthorized file download, and arbitrary file upload of executable files. These flaws enable low-privileged authenticated users to escalate privileges, access unauthorized files, and potentially execute malicious code, posing significant security risks.
Sources: Cvefeed, Feedburner, Securityaffairs
https://cvefeed.io/vuln/detail/CVE-2024-50619
5. Critical Authentication Bypass Vulnerabilities Found in ZLAN5143D Devices
Two critical vulnerabilities (CVE-2026-25084 and CVE-2026-24789) affect ZLAN5143D devices, allowing attackers to bypass authentication and remotely change device passwords via unprotected internal URLs and API endpoints. These flaws expose devices to unauthorized access and control, posing significant security risks.
Sources: Cvefeed
https://cvefeed.io/vuln/detail/CVE-2026-25084
Stay sharp. Stay secure.
#NerdieNews#InfoSec#CyberSecurity#TechNews#DataSecurity#CyberThreats
Post summary
The article announces several high‑severity CVEs across multiple products, providing basic technical details and risk assessments but no PoC, exploit code, or evidence of active exploitation.
Vulnerabilidad crítica en WPvivid Backup & Migration (CVE-2026-1357)
https://nksistemas.com/vulnerabilidad-critica-en-wpvivid-backup-migration-cve-2026-1357/
Post summary
The article headline references a critical vulnerability (CVE‑2026‑1357) in WPvivid Backup & Migration, but no additional details or actionable information are provided in the text.
"PCP replaced" - the metric tracked by PCPJack's C2.
PCPJack is a Linux credential-stealing worm disclosed May 7, 2026 by SentinelLabs. It exploits five CVEs to spread:
- CVE-2025-29927 (Next.js middleware auth bypass)
- CVE-2025-55182 "React2Shell" (Next.js Server Actions deserialization)
- CVE-2026-1357 (WPVivid Backup unauth file upload)
- CVE-2025-9501 (W3 Total Cache PHP injection via cached mfunc)
- CVE-2025-48703 (CentOS Web Panel Filemanager shell injection)
http://bootstrap.sh kills competing TeamPCP processes before installing itself, then drops six Python scripts handling orchestration, credential parsing, lateral movement, encryption, cloud-IP refresh, and port scanning.
Lateral movement targets SSH, Kubernetes, Docker, Redis, RayML, MongoDB. Persistence via systemd, cron, Redis rewrites, and privileged containers. Targets pulled from Common Crawl parquet files. http://check.sh probes IMDS endpoints and Kubernetes service accounts.
Credentials harvested cover Anthropic, OpenAI, HashiCorp Vault, 1Password, Slack, SSH keys, and WordPress configs. Exfil uses X25519 ECDH + ChaCha20-Poly1305, 2800-byte chunks, to Telegram.
SentinelLabs links it to a likely former TeamPCP affiliate from tooling overlap. No cryptomining, unlike TeamPCP - the C2 explicitly tracks "PCP replaced" successes.
A worm built to evict its predecessor and harvest the cloud underneath.
Post summary
PCPJack is a Linux credential‑stealing worm that exploits five CVEs to move laterally and persist, clearly demonstrating active exploitation. The publication provides detailed technical vulnerability information but no mention of patches or PoC code.
🚨 [CRITICAL] Active exploitation detected: CVE-2026-1357
Exploit in the wild confirmed for CVE-2026-1357 (CVSS 9.8). The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulner...
🔗 http://ctiwatch.cloud/alerts
#ZeroDay#ExploitInWild#CyberSecurity
Post summary
The tweet reports active exploitation of CVE-2026‑1357 against the WPvivid Backup & Migration WordPress plugin, highlighting a high CVSS score but offering no patch or exploit details.