Nearly 1 million WordPress websites could be at risk from this serious plugin security flaw


  • WPvivid Backup & Migration plugin vulnerable to critical RCE vulnerability CVE-2026-1357
  • Exploitation requires enabling the “receive a backup from another site” option, with an attack window of 24 hours.
  • Patch released in version 0.9.123 (January 28); users are advised to upgrade immediately

WPvivid Backup & Migration, a WordPress plugin with nearly 1 million installations, is vulnerable to a critical severity flaw that allows malicious actors to execute malicious code remotely.

Although this seems worrying, the bug has some limitations that make it somewhat difficult to exploit.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top