info: name:WordPress WPvivid Backup & Migration Plugin <= 0.9.116 - Authenticated Arbitrary File Upload author:pussycat0x severity:high description:| The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpvivid_upload_import_files' function in all versions up to, and including, 0.9.116. impact:| An authenticated attacker can upload arbitrary files, including PHP files, which can lead to remote code execution, complete system compromise, and unauthorized access to sensitive data. remediation:| Update the WPvivid Backup & Migration plugin to a version that addresses this vulnerability or remove the plugin if no fix is available. classification: cvss-metrics:CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H cvss-score:8.8 cve-id:CVE-2025-5961 cwe-id:CWE-434 metadata: max-request:4 vendor:wpvivid product:migration-backup-staging framework:wordpress shodan-query:http.component:"wordpress" reference: -https://github.com/Nxploited/CVE-2025-5961 tags:cve,cve2025,wordpress,intrusive,wpvivid,plugin,authenticated,file-upload,backup