Nearly a million WordPress sites may be at risk due to this serious plugin security flaw


  • WPvivid Backup & Migration plugin vulnerable to critical RCE flaw CVE-2026-1357
  • Exploitation requires “receive backup from another site” enabled, with 24-hour attack window
  • Patch released in version 0.9.123 (January 28); users are encouraged to upgrade immediately

WPvivid Backup & Migration, a WordPress plugin with nearly one million installations, is vulnerable to a critical severity flaw that allows threat actors to run malicious code remotely.

While it sounds ominous, the bug has a few limitations that make exploitation somewhat difficult.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top