Saturday, August 15, 2026
LIVE
Ugandan villages still contest land titles as oil development advances///Nigerian Troops Repel Bandit Attack on Kebbi Workers///NLC Queries Lagos Chairman Over Ties to Pro-Tinubu Group///Côte d’Ivoire Names New Leader for Blé Goudé’s COJEP Party///United States Highlights Civilian Deaths in Nigeria Terror Fight///Zimbabwe Pledges New Ferry and Road Repair After Lake Kariba Disaster///Ebola death toll reaches two thousand in Democratic Republic of the Congo///Forced Conscription Reports Emerge Across Ethiopia Oromia Region///Ebola outbreak reaches displacement camps in eastern Democratic Republic of the Congo///Hacking Group Claims Data Theft from Shell and Other Global Firms///Turkey warns of radical measures if Israel rejects Gaza peace deal terms///Nigerian President Urged to Engage Niger Delta Leader for Reelection Campaign///Ugandan villages still contest land titles as oil development advances///Nigerian Troops Repel Bandit Attack on Kebbi Workers///NLC Queries Lagos Chairman Over Ties to Pro-Tinubu Group///Côte d’Ivoire Names New Leader for Blé Goudé’s COJEP Party///United States Highlights Civilian Deaths in Nigeria Terror Fight///Zimbabwe Pledges New Ferry and Road Repair After Lake Kariba Disaster///Ebola death toll reaches two thousand in Democratic Republic of the Congo///Forced Conscription Reports Emerge Across Ethiopia Oromia Region///Ebola outbreak reaches displacement camps in eastern Democratic Republic of the Congo///Hacking Group Claims Data Theft from Shell and Other Global Firms///Turkey warns of radical measures if Israel rejects Gaza peace deal terms///Nigerian President Urged to Engage Niger Delta Leader for Reelection Campaign///
Subscribe
Africa
Independent · Digital
The African Herald
PoliticsAI-assisted

WordPress Backup Plugin Vulnerability Exposes 800,000 Sites to Remote Code Execution Attacks

A critical vulnerability has been identified in the WPvivid Backup & Migration plugin, impacting over 800,000 WordPress websites through potential remote code execution (RCE) attacks.

A critical vulnerability has been identified in the WPvivid Backup & Migration plugin, impacting over 800,000 WordPress websites through potential remote code execution (RCE) attacks.

The vulnerability, designated as CVE-2026-1357, has been assigned a CVSS score of 9.8. It allows unauthenticated attackers to upload arbitrary files and execute malicious PHP code. This issue affects all WPvivid Backup versions up to and including 0.9.123, resulting from improper error handling during the plugin’s RSA decryption process and insufficient file path sanitization.

Upon RSA decryption failure, the plugin incorrectly passes a false value to the AES cipher initialization routine, interpreted as a string of null bytes. This allows attackers to encrypt payloads using a predictable null-byte key. Additionally, the lack of proper sanitation for filenames from encrypted payloads enables directory traversal, allowing files to be written to publicly accessible locations.

A critical vulnerability has been identified in the WPvivid Backup & Migration plugin, impacting over 800,000 WordPress websites through potential remote code execution (RCE) attacks.
Kwame Osei · The African Herald

The vulnerability was discovered and responsibly reported by Lucas Montes (NiRoX) through the Wordfence Bug Bounty Program. A bounty of $2,145 was awarded for this finding. The vendor addressed the issue by implementing an empty check for the $key value in the decrypt_message() function, ensuring decryption failures halt processing and introducing strict file extension validation.

Exploitation of this vulnerability could result in arbitrary file uploads and execution, leading to potential full site compromise. Site owners are advised to update to WPvivid Backup version 0.9.124 or later to mitigate this risk.

Advertisement

Wordfence issued a firewall rule on Jan 22, 2026, for Premium, Care, and Response customers, with free user protection scheduled for Feb 21, 2026. The WPvivid development team released the patched version, 0.9.124, on Jan 28, 2026, following a prompt response to the report.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories