CyberRota Analysis
AI-GeneratedThe WPvivid Backup, Migration & Staging plugin for WordPress prior to version 0.9.134 is vulnerable due to inadequate validation of user-supplied paths in its file deletion process, which could enable administrators to delete arbitrary files on the server, including those outside the web root. This vulnerability poses a significant risk of data loss and server misconfiguration. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation.
Original NVD Description
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before using it in a file deletion routine, allowing administrators to delete arbitrary files on the server, including files outside the web root.