CVE-2026-1357Disclosure

CRITICALCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 7 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions up to and including 0.9.123. This is due to improper error handling in the RSA decryption process combined with a lack of path sanitization when writing uploaded files. When the plugin fails to decrypt a session key using openssl_private_decrypt(), it does not terminate execution and instead passes the boolean false value to the phpseclib library's AES cipher initialization. The library treats this false value as a string of null bytes, allowing an attacker to encrypt a malicious payload using a predictable null-byte key. Additionally, the plugin accepts filenames from the decrypted payload without sanitization, enabling directory traversal to escape the protected backup directory. This makes it possible for unauthenticated attackers to upload arbitrary PHP files to publicly accessible directories and achieve Remote Code Execution via the wpvivid_action=send_to_site parameter.

8.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 5 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 40 mentions across 17 observed days

What's happening

  • Active exploitation reported across 5 signals
  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 14 signals
  • Technical details provided in 31 signals
  • Disclosure: 20 classified signals
  • Peaked 13d ago at 7 mentions (2026-02-13); latest day: 1
  • 40 total mentions across 17 days

Deep dive

Activity timeline40 mentions / 17d
02457Mentions · 2026-02-10: 1Mentions · 2026-02-11: 5Mentions · 2026-02-12: 5Mentions · 2026-02-13: 7Mentions · 2026-02-15: 1Mentions · 2026-02-16: 4Mentions · 2026-02-17: 4Mentions · 2026-02-18: 2Mentions · 2026-02-19: 2Mentions · 2026-02-20: 2Mentions · 2026-02-23: 1Mentions · 2026-03-10: 1Mentions · 2026-03-12: 1Mentions · 2026-04-11: 1Mentions · 2026-05-07: 1Mentions · 2026-05-08: 1Mentions · 2026-07-24: 1PoC Mentioned / Linked · 2026-02-11: 2PoC Mentioned / Linked · 2026-02-13: 1PoC Mentioned / Linked · 2026-02-17: 1PoC Mentioned / Linked · 2026-02-20: 1PoC Mentioned / Linked · 2026-03-10: 1Exploit Tool / Code · 2026-02-11: 1Exploit Tool / Code · 2026-02-20: 1Exploit Tool / Code · 2026-03-10: 1Active Exploitation · 2026-02-16: 1Active Exploitation · 2026-03-10: 1Active Exploitation · 2026-04-11: 1Active Exploitation · 2026-05-07: 1Active Exploitation · 2026-05-08: 1Patch / Workaround · 2026-02-11: 2Patch / Workaround · 2026-02-12: 3Patch / Workaround · 2026-02-13: 1Patch / Workaround · 2026-02-15: 1Patch / Workaround · 2026-02-16: 2Patch / Workaround · 2026-02-19: 2Patch / Workaround · 2026-02-20: 2Patch / Workaround · 2026-07-24: 1Technical Details · 2026-02-10: 1Technical Details · 2026-02-11: 4Technical Details · 2026-02-12: 4Technical Details · 2026-02-13: 6Technical Details · 2026-02-15: 1Technical Details · 2026-02-16: 4Technical Details · 2026-02-17: 2Technical Details · 2026-02-19: 1Technical Details · 2026-02-20: 2Technical Details · 2026-02-23: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-12: 1Technical Details · 2026-04-11: 1Technical Details · 2026-05-08: 1Technical Details · 2026-07-24: 102-1002-1102-1202-1302-1502-1602-1702-1802-1902-2002-2303-1003-1204-1105-0705-0807-24
Signal classification5 categories
Disclosure
2050.0%
Patch
1025.0%
Active Exploitation
512.5%
General
37.5%
PoC
25.0%
Referenced assets37 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-101
Disclosure1
2026-02-115
Disclosure2General1Patch1PoC1
2026-02-125
Disclosure1General1Patch3
2026-02-137
Disclosure6Patch1
2026-02-151
Patch1
2026-02-164
Active Exploitation1Disclosure2Patch1
2026-02-174
Disclosure4
2026-02-182
Disclosure1General1
2026-02-192
Patch2
2026-02-202
Patch1PoC1
2026-02-231
Disclosure1
2026-03-101
Active Exploitation1
2026-03-121
Disclosure1
2026-04-111
Active Exploitation1
2026-05-071
Active Exploitation1
2026-05-081
Active Exploitation1
2026-07-241
Disclosure1
Full discourse20 posts
  • NiRoX@NiRoXoRiN
    PoC

    💥 Dropped my PoC for CVE-2026-1357 (9.8) — WPvivid Backup & Migration (900k+ installs) Unauth → Arbitrary file upload → RCE 🚨 Root cause: cryptographic fail-open + path traversal combo. Full PoC and write up👇 https://github.com/LucasM0ntes/POC-CVE-2026-1357

    Post summary

    The tweet announces a proof‑of‑concept for CVE‑2026‑1357, demonstrating unauthenticated arbitrary file upload leading to remote code execution on the WPvivid plugin, and links to the GitHub repository with the PoC.

    013047132.7K
    35 followersView on X
  • モーくん🐮|WordPress × セキュリティ@accell_mo_kun
    Disclosure

    おはモー🐮 バックアップ系WPvividに未認証で乗っ取れる脆弱性(CVE-2026-1357)が出たモー🐮 フォーム系も7万サイト超が影響、修正版が出ても普段開かない場所は放置のままモー🐄 守る道具が一番の裏口、今日棚卸しするモー🐮 #おは戦80725jd🍩 #WordPress

    Post summary

    A new unauthenticated takeover vulnerability (CVE‑2026‑1357) in the WPvivid backup plugin has been disclosed, affecting more than 70,000 sites; a patch has been issued but many users have yet to update.

    0001501.1K
    911 followersView on X
  • NiRoX@NiRoXoRiN
    Disclosure

    🚨 CRITICAL WORDPRESS VUNERABIITY 🚨 Found a pre-auth RCE via a 2-bug exploit chain in WPvivid Backup & Migration (700K+ active installs). 💥 CVSS: 9.8 (CRITICAL) 🆔 CVE-2026-1357 🙏 Thanks to @wordfence 💰 $2,145 bounty paid More to come 👀🔥 and update NOW!! https://t.co/PAgsUiBLnD

    Post summary

    The tweet announces a critical WordPress vulnerability (CVE‑2026‑1357) with a pre‑authentication RCE and a high CVSS score, noting a bounty payout but providing no PoC, exploit code, or patch information.

    20082558
    35 followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    CVE-2026-1357: WordPress Plugin RCE Exposes Sites to Full Takeover https://securityboulevard.com/2026/02/cve-2026-1357-wordpress-plugin-rce-exposes-sites-to-full-takeover/ 『(直訳)WordPressプラグイン「WPvivid Backup & Migration」に重大な脆弱性が発見され、認証されていない攻撃者が公開されているウェブサイトに任意のPHPファイルをアップロード・実行できる可能性があります』

    Post summary

    A critical RCE vulnerability in the WordPress plugin WPvivid Backup & Migration permits unauthenticated attackers to upload and run arbitrary PHP, potentially leading to full site takeover.

    000411.0K
    11.3K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    New PCPJack worm targets cloud infrastructure, stealing credentials from Docker/Kubernetes/Redis while actively removing TeamPCP infections. Exploits 5 recent CVEs including CVE-2025-29927 and CVE-2026-1357 for initial access. #DFIR_Radar https://t.co/4pMlgIN6MQ

    Post summary

    The post reports that the PCPJack worm actively exploits CVE-2025-29927 and CVE-2026-1357 for initial access in cloud environments.

    100111.1K
    1.7K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-1357 - critical 🚨 WPvivid Backup & Migration <= 0.9.123 - Arbitrary File Upload > WPvivid Backup & Migration plugin for WordPress <= 0.9.123 contains an unauthenticate... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-1357 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post announces CVE-2026-1357, an arbitrary file upload flaw in WPvivid Backup & Migration plugin up to version 0.9.123, without providing exploits, patches, or evidence of active attacks.

    00012169
    902 followersView on X
  • Directoratul Național de Securitate Cibernetică@DNSC_RO
    Disclosure

    🚨 ALERTĂ: Vulnerabilitate critică în plugin-ul Wordpress WPvivid Backup & Migration (CVE-2026-1357) 🔗 Mai multe detalii, în alerta de pe site-ul DNSC: 👉 https://www.dnsc.ro/citeste/alerta-vulnerabilitate-critica-in-plugin-ul-wordpress-wpvivid-backup-migration #DNSC #CyberSecurity #CyberAlert #Vulnerability #CVE #WordPress https://t.co/vB6ONL4wFG

    Post summary

    The tweet announces a critical vulnerability (CVE-2026-1357) in the WPvivid WordPress plugin and directs readers to a DNSC alert for further details.

    00030160
    4.6K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Critical WPvivid Backup flaw (CVE-2026-1357) exposes 800K+ WordPress sites to unauth RCE WPvivid Backup & Migration (≤ 0.9.123) is vulnerable to an unauthenticated arbitrary file upload that can be weaponized for remote code execution/site takeover when untrusted backup-transfer paths are reachable; update to 0.9.124+ immediately and audit for unexpected uploads/webshells. Public details cite RSA decryption error-handling + path sanitization gaps enabling attackers to write files to public directories. 🎯 Target: Global/WordPress (Web Hosting & SMEs) #️⃣ Category: #Vulnerability #BlueTeam #CyberIntel 🔗 URL: https://cyberpress.org/wordpress-backup-plugin-exploit/

    Post summary

    The post announces a critical unauthenticated RCE flaw in WPvivid Backup (CVE-2026-1357), provides technical details of the vulnerability, links to additional information, and urges an immediate upgrade to version 0.9.124+ to mitigate the risk.

    02010140
    191 followersView on X
  • Nxploited@Nxploited
    Active Exploitation

    New critical 0‑day in the wild: CVE‑2026‑1357 – WPvivid Backup & Migration ≤ 0.9.123 PoC: https://github.com/Nxploited/CVE-2026-1357 Telegram: https://t.me/KNxploited/ #WordPress #CVE2026 #BugBounty #RCE #WPvivid #Infosec #CyberSecurity #Exploit #Pentest

    Post summary

    The post announces that CVE‑2026‑1357, a critical 0‑day affecting WPvivid Backup & Migration, is being used in the wild, with a PoC link provided for exploitation.

    00011201
    91 followersView on X
  • Ostorlab@OstorlabSec
    PoC

    🚨 New Blog Post: CVE-2026-1357 (CVSS 9.8) — Unauthenticated RCE in WPvivid Backup Plugin A cryptographic fail-open + path traversal chain = full remote code execution without credentials. In our latest technical breakdown, we dissect how WPvivid Backup & Migration (≤ 0.9.123) can be exploited to write arbitrary files and drop a web shell, and how version 0.9.124 fixes it. If you run WordPress or monitor KEVs at scale, this one matters. 👉 Read the full analysis and PoC walkthrough on our blog : https://blog.ostorlab.co/cve-2026-1357-unauthenticated-rce-wpvivid.html #CVE20261357 #WordPressSecurity

    Post summary

    The article announces a high‑severity RCE in WPvivid Backup, provides a PoC walkthrough, technical details, and notes that the next plugin version resolves the flaw.

    0101062
    583 followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    CVE-2026-1357 Critical #RCE in WPvivid Backup & Migration plugin affects versions ≤ 0.9.123 and has a CVSS 9.8 severity score. Unauthenticated attackers can exploit improper RSA error handling and unsanitized file paths to upload arbitrary PHP files and execute remote code ⚠️ Why it matters: Backup/migration workflows now create an unexpected entry point for full site takeover on many WordPress sites. 🛠 Fix: Update the plugin to 0.9.124 or later immediately and review any unexpected files if the vulnerable feature was used. #WordPressSecurity #CVE #WebSecurity #RemoteCodeExecution #CyberThreats #Malware #CyberSecurity

    Post summary

    The post highlights a critical RCE in WPvivid Backup & Migration plugin (CVE‑2026‑1357) with a CVSS 9.8 score and advises updating to 0.9.124 or later, but does not report active exploitation or provide an exploit tool.

    1000048
    37 followersView on X
  • iototsecnews@iototsecnews
    Patch

    WordPress WPvivid Backup の脆弱性 CVE-2026-1357 が FIX:ファイル・アップロード機能の不備と RCE https://iototsecnews.jp/2026/02/12/wordpress-backup-plugin-vulnerability-exposes-800000-sites-to-remote-code-execution-attacks/ この問題の原因は、バックアップ・プラグイン WPvivid において、データの暗号を解く際の例外処理と、保存されるファイル名のチェックという、2 つの重要な安全機能が不十分にしか働いていなかったことにあります。一つ目の不備は、外部から届いたデータの暗号 (RSA) 解除に失敗したときに、プログラムが処理を中断せずに “false” 状態のまま、強引に先へ進めてしまったことです。それにより、本来は厳重に守られるべき通信が、誰でも推測できる鍵で開けられる状態になっています。二つ目の不備は、届けられたファイル名の中にフォルダを遡る記号 “../ など” が含まれていても、それを適切に排除せず受け入れてしまったことです。このディレクトリ・トラバーサルと呼ばれる欠陥により、攻撃者はバックアップ用の専用フォルダを飛び越えて、Web サーバ上の本来はアクセス不能な場所にファイルを送り込むことが可能になります。ご利用のチームは、ご注意ください。 #CVE20261357 #Vulnerability #WordPress #WPvividBackup

    Post summary

    The post announces that CVE‑2026‑1357 in the WPvivid backup plugin has been fixed, detailing the RCE mechanism via RSA decryption and directory traversal vulnerabilities.

    01000125
    484 followersView on X
  • CIBERED@ciberedx
    Disclosure

    🚨 Vulnerabilidad crítica en WPvivid Backup & Migration afecta a 900.000 sitios de WordPress https://cibered.com/ciberseguridad/noticias/wpvivid-backup-migration-rce-cve-2026-1357/ #WordPress #Vulnerabilidades #Ciberseguridad #Cibered

    Post summary

    A critical remote code execution vulnerability (CVE‑2026‑1357) in WPvivid Backup & Migration affecting up to 900,000 WordPress sites has been reported, with no evidence of PoC, active exploitation, or patch details provided.

    0000149
    1.5K followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    #CVE-2026-1357 — Critical #WordPress Plugin Vulnerability The WPvivid Backup & Migration plugin (≤ 0.9.123) allows unauthenticated arbitrary file upload due to improper RSA error handling and missing path sanitization. Why this matters: Attackers can upload a malicious PHP file and execute it on the server — leading to Remote Code Execution (RCE) and full site takeover. What to do now: • Update to the latest patched version immediately • Audit recent uploads and admin users • Scan for unexpected PHP files/backdoors How to reduce future risk: • Keep plugins updated promptly • Remove unused plugins • Restrict file upload capabilities • Monitor for anomalous file changes Security gaps in upload logic can escalate quickly — patching speed is critical. #WordPressSecurity #CyberThreats #Malware #CVE

    Post summary

    The tweet announces a critical file‑upload vulnerability in WPvivid Backup & Migration (CVE‑2026‑1357), warns of remote code execution risks, and urges immediate patching and security checks.

    1000048
    37 followersView on X
  • Alborz Safe@EthicalSafe
    Disclosure

    برای یکی از معروفترین پلاگین های این CMS ، یعنی WPvivid Backup آسیب پذیری با کد شناسایی CVE-2026-1357 از نوع RCE منتشر شده است ، این آسیب پذیری به هکرها اجازه upload فایل PHP و اجرا کردن آن را می دهد. https://t.co/eHDnlIS2WG

    Post summary

    A newly disclosed RCE vulnerability (CVE‑2026‑1357) in the WPvivid Backup plugin permits attackers to upload and execute PHP files.

    0001049
    4 followersView on X
  • Hacker Affairs@hackeraffairs
    Disclosure

    🚨 WordPress Backup Plugin Vulnerability Exposes 900K Sites A critical vulnerability in the WPvivid Backup & Migration plugin for WordPress can be exploited to achieve remote code execution by uploading arbitrary files without authentication. Tracked as CVE-2026-1357, the flaw impacts all plugin versions up to and including 0.9.123, with exposure requiring the non-default "receive backup from another site" option to be enabled and website takeover described as the end result. 🔗Details → https://hackeraffairs.com/wordpress-backup-plugin-vulnerability-exposes-900k-sites/

    Post summary

    The post announces CVE-2026-1357 for the WPvivid Backup & Migration plugin, detailing how it enables remote code execution through unauthenticated file uploads and the specific conditions that trigger it.

    0001085
    27 followersView on X
  • NerdieNews@NewsNerdie
    Disclosure

    Today's Top Cybersecurity News – February 13, 2026 1. Critical WPvivid Backup Flaw (CVSS 9.8) Exposes 800K WordPress Sites A critical vulnerability (CVE-2026-1357) in the WPvivid Backup plugin affects over 800,000 WordPress sites, potentially exposing sensitive backup data. This flaw poses a significant risk of data compromise and site integrity loss if exploited. Sources: Bleepingcomputer, Cvefeed, Darkreading, Feedburner, Gbhackers, Infosecurity-Magazine, Intel471, Malwarebytes, Mandiant, Proofpoint, Securityweek, Therecord https://securityonline.info/null-byte-nightmare-critical-wpvivid-backup-flaw-cvss-9-8-exposes-800k-wordpress-sites/ 2. Critical SandboxJS Vulnerability (CVE-2026-25881) Enables Host Takeover A critical flaw in SandboxJS allows attackers to escape the sandbox environment and execute malicious code on the host system. This vulnerability poses a severe risk to applications relying on SandboxJS for secure JavaScript execution. Sources: Cvefeed, Microsoft https://securityonline.info/sandbox-breakout-critical-sandboxjs-flaw-cve-2026-25881-allows-host-takeover/ 3. Multiple High and Critical Vulnerabilities Including Authentication Bypass, Buffer Overflows, and Path Traversal A series of critical and high-severity vulnerabilities have been disclosed affecting various software products including PRO-7070, OwnCloud, SpotAuditor, and others. These vulnerabilities enable attackers to bypass authentication, execute arbitrary code via buffer overflows and stack overflows, perform path traversal to access sensitive files, and disclose usernames, posing significant risks to affected systems. Immediate patching and mitigation are recommended to prevent unauthorized access and potential system compromise. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2019-25335 4. Multiple Critical Vulnerabilities in CIPPlanner CIPAce Allow Privilege Escalation and Arbitrary File Access CIPPlanner CIPAce versions before 9.17 contain multiple severe vulnerabilities including account privilege escalation, unauthorized file download, and arbitrary file upload of executable files. These flaws enable low-privileged authenticated users to escalate privileges, access unauthorized files, and potentially execute malicious code, posing significant security risks. Sources: Cvefeed, Feedburner, Securityaffairs https://cvefeed.io/vuln/detail/CVE-2024-50619 5. Critical Authentication Bypass Vulnerabilities Found in ZLAN5143D Devices Two critical vulnerabilities (CVE-2026-25084 and CVE-2026-24789) affect ZLAN5143D devices, allowing attackers to bypass authentication and remotely change device passwords via unprotected internal URLs and API endpoints. These flaws expose devices to unauthorized access and control, posing significant security risks. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-25084 Stay sharp. Stay secure. #NerdieNews #InfoSec #CyberSecurity #TechNews #DataSecurity #CyberThreats

    Post summary

    The article announces several high‑severity CVEs across multiple products, providing basic technical details and risk assessments but no PoC, exploit code, or evidence of active exploitation.

    0001056
    54 followersView on X
  • nksistemas@nksistemas
    General

    Vulnerabilidad crítica en WPvivid Backup & Migration (CVE-2026-1357) https://nksistemas.com/vulnerabilidad-critica-en-wpvivid-backup-migration-cve-2026-1357/

    Post summary

    The article headline references a critical vulnerability (CVE‑2026‑1357) in WPvivid Backup & Migration, but no additional details or actionable information are provided in the text.

    01000171
    6.2K followersView on X
  • SecureChap@SecureChap
    Active Exploitation

    "PCP replaced" - the metric tracked by PCPJack's C2. PCPJack is a Linux credential-stealing worm disclosed May 7, 2026 by SentinelLabs. It exploits five CVEs to spread: - CVE-2025-29927 (Next.js middleware auth bypass) - CVE-2025-55182 "React2Shell" (Next.js Server Actions deserialization) - CVE-2026-1357 (WPVivid Backup unauth file upload) - CVE-2025-9501 (W3 Total Cache PHP injection via cached mfunc) - CVE-2025-48703 (CentOS Web Panel Filemanager shell injection) http://bootstrap.sh kills competing TeamPCP processes before installing itself, then drops six Python scripts handling orchestration, credential parsing, lateral movement, encryption, cloud-IP refresh, and port scanning. Lateral movement targets SSH, Kubernetes, Docker, Redis, RayML, MongoDB. Persistence via systemd, cron, Redis rewrites, and privileged containers. Targets pulled from Common Crawl parquet files. http://check.sh probes IMDS endpoints and Kubernetes service accounts. Credentials harvested cover Anthropic, OpenAI, HashiCorp Vault, 1Password, Slack, SSH keys, and WordPress configs. Exfil uses X25519 ECDH + ChaCha20-Poly1305, 2800-byte chunks, to Telegram. SentinelLabs links it to a likely former TeamPCP affiliate from tooling overlap. No cryptomining, unlike TeamPCP - the C2 explicitly tracks "PCP replaced" successes. A worm built to evict its predecessor and harvest the cloud underneath.

    Post summary

    PCPJack is a Linux credential‑stealing worm that exploits five CVEs to move laterally and persist, clearly demonstrating active exploitation. The publication provides detailed technical vulnerability information but no mention of patches or PoC code.

    000001.3K
    153 followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [CRITICAL] Active exploitation detected: CVE-2026-1357 Exploit in the wild confirmed for CVE-2026-1357 (CVSS 9.8). The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulner... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    The tweet reports active exploitation of CVE-2026‑1357 against the WPvivid Backup & Migration WordPress plugin, highlighting a high CVSS score but offering no patch or exploit details.

    0000074
    5.6K followersView on X

Explore more