CVE-2026-1357: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-1357 is a critical unauthenticated arbitrary file upload vulnerability in the Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress, affecting versions up to and including 0.9.123. The flaw allows remote, unauthenticated attackers to upload arbitrary PHP files to publicly accessible directories and achieve Remote Code Execution (RCE). It was published on February 11, 2026, and carries a CVSS v3.1 base score of 9.8 (Critical) (Wordfence, Red Hat CVE). The plugin is installed on approximately 800,000–900,000 WordPress sites, making the potential attack surface extremely large (BleepingComputer).

Technical details

The vulnerability (CWE-434: Unrestricted Upload of File with Dangerous Type) stems from two compounding flaws in the plugin's file transfer functionality (Wordfence). First, when RSA decryption of a session key fails via openssl_private_decrypt(), the plugin does not terminate execution; instead, it passes the boolean false return value to the phpseclib AES cipher, which treats false as a string of null bytes — creating a fully predictable encryption key. Second, filenames extracted from the decrypted payload are accepted without path sanitization, enabling directory traversal sequences (e.g., ../../) to escape the designated backup directory and write files to arbitrary, web-accessible locations. An attacker exploits this via the wpvivid_action=send_to_site parameter in a POST request to wp-admin/admin-ajax.php, requiring no authentication or user interaction (Ostorlab Blog, Security Boulevard). Public PoC exploit code is available on GitHub (GitHub PoC).

Impact

Successful exploitation grants an unauthenticated remote attacker full control over the affected WordPress installation by placing a PHP web shell in a publicly accessible directory and executing arbitrary server-side commands. This enables complete confidentiality, integrity, and availability compromise — including theft of database credentials and user data, site defacement, malware installation, and use of the server as a pivot point for lateral movement within the hosting environment (Wordfence, Ostorlab Blog). The vulnerability has been actively weaponized by the PCPJack cloud worm, which exploits CVE-2026-1357 among other CVEs to spread across cloud environments, steal credentials, and displace competing threat actors from compromised systems (SentinelOne, BleepingComputer PCPJack).

Exploitability

Multiple public proof-of-concept exploits exist on GitHub (e.g., itsismarcos/Exploit-CVE-2026-1357, Nxploited/CVE-2026-1357, 0xAshwesker/CVE-2026-1357, masterwok/PoC-CVE-2026-1357) and have been indexed by Sploitus and Vulners (Sploitus). The vulnerability is being actively exploited in the wild by the PCPJack worm — a modular cloud credential-theft tool that leverages this CVE alongside four others to propagate worm-like across Docker, Kubernetes, Redis, and MongoDB environments (The Hacker News, SentinelOne). Nuclei detection templates have been merged into the ProjectDiscovery repository, and Qualys has published detection IDs (530925, 733680). The EPSS score is 0.00524 (as of initial publication), though active exploitation significantly elevates real-world risk. No CISA KEV listing has been confirmed in the available data.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running WPvivid Backup & Migration plugin ≤ 0.9.123 using tools like WPScan, Shodan, or Censys, or by checking /wp-content/plugins/wpvivid-backuprestore/readme.txt for version disclosure.
  2. Craft null-byte AES key: Since the plugin's RSA decryption failure results in a null-byte AES key, the attacker encrypts a malicious payload (containing a PHP web shell and a traversal filename) using AES with a key composed entirely of null bytes (\x00 repeated).
  3. Construct malicious payload: The encrypted payload includes a crafted filename using directory traversal (e.g., ../../uploads/shell.php) and PHP web shell content (e.g., <?php system($_GET['cmd']); ?>).
  4. Send exploit request: Submit an unauthenticated HTTP POST request to https://target.com/wp-admin/admin-ajax.php with the parameter action=wpvivid_action&wpvivid_action=send_to_site and the encrypted payload as the request body.
  5. Trigger file write: The plugin decrypts the payload using the null-byte key, extracts the traversal filename without sanitization, and writes the PHP file to the web-accessible directory (e.g., wp-content/uploads/shell.php).
  6. Execute arbitrary commands: Access the uploaded web shell via https://target.com/wp-content/uploads/shell.php?cmd=id to confirm RCE, then proceed with post-exploitation (credential harvesting, reverse shell, lateral movement) (Wordfence, Ostorlab Blog, Security Boulevard).

Indicators of compromise

  • Network: Unusual unauthenticated POST requests to wp-admin/admin-ajax.php with action=wpvivid_action and wpvivid_action=send_to_site parameters from unknown external IPs; outbound connections from the web server to attacker-controlled infrastructure following successful upload.
  • File System: Unexpected PHP files (especially with random or obfuscated names) appearing in wp-content/uploads/, wp-content/plugins/, or other web-accessible directories outside the designated WPvivid backup folder; files containing system(), exec(), passthru(), shell_exec(), or base64_decode() PHP functions.
  • Logs: Web server access logs showing POST requests to admin-ajax.php with wpvivid_action=send_to_site from unauthenticated sessions; subsequent GET requests to newly created PHP files in upload directories; PHP error logs showing AES decryption or phpseclib-related exceptions.
  • Process: Unusual child processes spawned by the PHP-FPM or Apache/Nginx worker process (e.g., bash, curl, wget, python3, nc) executing system commands; processes associated with PCPJack worm activity targeting Docker, Kubernetes, Redis, or MongoDB services (SentinelOne, Wordfence).
  • Malware Association: Presence of Sliver C2 implant artifacts or PCPJack worm components on compromised hosts (SentinelOne).

Mitigation and workarounds

Immediate action: Update the WPvivid Backup & Migration plugin to a version newer than 0.9.123 as soon as a patched release is available from the vendor. If no patch is yet available, deactivate or remove the plugin entirely to eliminate the attack surface (Wordfence). WAF rules: Deploy Web Application Firewall rules to block POST requests to admin-ajax.php containing wpvivid_action=send_to_site with suspicious binary or traversal payloads; Citrix NetScaler WAF signatures (v170-r1248) include coverage for this CVE (Citrix NetScaler). Detection: Use Nuclei templates (merged into ProjectDiscovery's repository) or Qualys detection IDs 530925/733680 to scan for vulnerable instances. Monitoring: Review web server logs for anomalous requests to admin-ajax.php and audit wp-content/uploads/ for unexpected PHP files.

Community reactions

Wordfence published the initial disclosure and noted that approximately 800,000 WordPress sites were affected, generating significant community attention (Wordfence). BleepingComputer and The Hacker News covered the vulnerability extensively, with BleepingComputer later reporting on the PCPJack worm's active exploitation of this CVE in cloud environments (BleepingComputer, The Hacker News). Security researchers on Reddit's r/WordpressPlugins and Infosec.exchange discussed the vulnerability's severity and the novel null-byte key bypass technique. SentinelOne's threat intelligence team published a detailed analysis of PCPJack's use of this CVE in worm-like cloud attacks, which was widely shared across the security community (SentinelOne).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management