Ironic but true: The popular WordPress backup plugin WPvivid Backup & Migration (900,000+ installs) had a critical vulnerability CVE-2026-1357 (CVSS 9.8) — Unauthenticated PHP file upload → RCE and full page download. The patch was released on January 28, 2026. (version 0.9.124 ), and a public PoC appeared in the days after.
Who is most affected?
Pages that have the (non-default) option "receive backup from another site" enabled are critically vulnerable. This narrows the actual range, but given the huge install base — check it out without delay.
What to do now
- Update WPvivid to version 0.9.124 or higher — now.
- If you're not using it, consider deactivating it until you update.
- Check for unknown
.phpfiles and admin accounts (a sign that the exploit has already been exploited).
Lesson: Security tools are also software with vulnerabilities — plugins need to be updated as soon as a patch is released, not "when I get there."
Are you using WPvivid and not sure if your site is clean? Send us the link — the diagnosis is free, and we'll get back to you within 5 minutes. Urgent repair →
WMD — Super fast support.