Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-19725

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
16/08/2026
Última modificación:
16/08/2026

Descripción

*** Pendiente de traducción *** The WPvivid — Backup, Migration &amp; Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an unauthenticated request before using it to build a log file path, allowing an attacker holding a site to site transfer key to create a log file in any existing writable directory of the site, including the web root.<br /> <br /> The file name always carries a fixed suffix and the contents are always the WPvivid — Backup, Migration &amp; Staging WordPress plugin before 0.9.131&amp;#39;s own log header, so only the location of the file is attacker controlled.

Impacto

Referencias a soluciones, herramientas e información