info: name: WordPress WPvivid Backup & Migration Plugin <=0.9.116- Authenticated Arbitrary File Upload author: pussycat0x severity: high description: | The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpvivid_upload_import_files' function in all versions up to, and including, 0.9.116. impact: | An authenticated attacker can upload arbitrary files, including PHP files, which can lead to remote code execution, complete system compromise, and unauthorized access to sensitive data. remediation: | Update the WPvivid Backup & Migration plugin to a version that addresses this vulnerability or remove the plugin if no fix is available. reference: - https://github.com/Nxploited/CVE-2025-5961 - https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpvivid-backuprestore/migration-backup-staging-wpvivid-backup-migration-09116-authenticated-administrator-arbitrary-file-upload classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H cvss-score:8.8 cve-id: CVE-2025-5961 cwe-id: CWE-434 metadata: verified:true max-request:4 publicwww--query:"/plugins/wpvivid-backuprestore/" tags: cve,cve2025,wordpress,,wp-plugin,intrusive,wpvivid-backuprestore,authenticated,file-upload,backup