
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1357 is a critical unauthenticated arbitrary file upload vulnerability in the Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress, affecting versions up to and including 0.9.123. The flaw allows remote, unauthenticated attackers to upload arbitrary PHP files to publicly accessible directories and achieve Remote Code Execution (RCE). It was published on February 11, 2026, and carries a CVSS v3.1 base score of 9.8 (Critical) (Wordfence, Red Hat CVE). The plugin is installed on approximately 800,000–900,000 WordPress sites, making the potential attack surface extremely large (BleepingComputer).
The vulnerability (CWE-434: Unrestricted Upload of File with Dangerous Type) stems from two compounding flaws in the plugin's file transfer functionality (Wordfence). First, when RSA decryption of a session key fails via openssl_private_decrypt(), the plugin does not terminate execution; instead, it passes the boolean false return value to the phpseclib AES cipher, which treats false as a string of null bytes — creating a fully predictable encryption key. Second, filenames extracted from the decrypted payload are accepted without path sanitization, enabling directory traversal sequences (e.g., ../../) to escape the designated backup directory and write files to arbitrary, web-accessible locations. An attacker exploits this via the wpvivid_action=send_to_site parameter in a POST request to wp-admin/admin-ajax.php, requiring no authentication or user interaction (Ostorlab Blog, Security Boulevard). Public PoC exploit code is available on GitHub (GitHub PoC).
Successful exploitation grants an unauthenticated remote attacker full control over the affected WordPress installation by placing a PHP web shell in a publicly accessible directory and executing arbitrary server-side commands. This enables complete confidentiality, integrity, and availability compromise — including theft of database credentials and user data, site defacement, malware installation, and use of the server as a pivot point for lateral movement within the hosting environment (Wordfence, Ostorlab Blog). The vulnerability has been actively weaponized by the PCPJack cloud worm, which exploits CVE-2026-1357 among other CVEs to spread across cloud environments, steal credentials, and displace competing threat actors from compromised systems (SentinelOne, BleepingComputer PCPJack).
Multiple public proof-of-concept exploits exist on GitHub (e.g., itsismarcos/Exploit-CVE-2026-1357, Nxploited/CVE-2026-1357, 0xAshwesker/CVE-2026-1357, masterwok/PoC-CVE-2026-1357) and have been indexed by Sploitus and Vulners (Sploitus). The vulnerability is being actively exploited in the wild by the PCPJack worm — a modular cloud credential-theft tool that leverages this CVE alongside four others to propagate worm-like across Docker, Kubernetes, Redis, and MongoDB environments (The Hacker News, SentinelOne). Nuclei detection templates have been merged into the ProjectDiscovery repository, and Qualys has published detection IDs (530925, 733680). The EPSS score is 0.00524 (as of initial publication), though active exploitation significantly elevates real-world risk. No CISA KEV listing has been confirmed in the available data.
/wp-content/plugins/wpvivid-backuprestore/readme.txt for version disclosure.\x00 repeated).../../uploads/shell.php) and PHP web shell content (e.g., <?php system($_GET['cmd']); ?>).https://target.com/wp-admin/admin-ajax.php with the parameter action=wpvivid_action&wpvivid_action=send_to_site and the encrypted payload as the request body.wp-content/uploads/shell.php).https://target.com/wp-content/uploads/shell.php?cmd=id to confirm RCE, then proceed with post-exploitation (credential harvesting, reverse shell, lateral movement) (Wordfence, Ostorlab Blog, Security Boulevard).wp-admin/admin-ajax.php with action=wpvivid_action and wpvivid_action=send_to_site parameters from unknown external IPs; outbound connections from the web server to attacker-controlled infrastructure following successful upload.wp-content/uploads/, wp-content/plugins/, or other web-accessible directories outside the designated WPvivid backup folder; files containing system(), exec(), passthru(), shell_exec(), or base64_decode() PHP functions.admin-ajax.php with wpvivid_action=send_to_site from unauthenticated sessions; subsequent GET requests to newly created PHP files in upload directories; PHP error logs showing AES decryption or phpseclib-related exceptions.bash, curl, wget, python3, nc) executing system commands; processes associated with PCPJack worm activity targeting Docker, Kubernetes, Redis, or MongoDB services (SentinelOne, Wordfence).Immediate action: Update the WPvivid Backup & Migration plugin to a version newer than 0.9.123 as soon as a patched release is available from the vendor. If no patch is yet available, deactivate or remove the plugin entirely to eliminate the attack surface (Wordfence). WAF rules: Deploy Web Application Firewall rules to block POST requests to admin-ajax.php containing wpvivid_action=send_to_site with suspicious binary or traversal payloads; Citrix NetScaler WAF signatures (v170-r1248) include coverage for this CVE (Citrix NetScaler). Detection: Use Nuclei templates (merged into ProjectDiscovery's repository) or Qualys detection IDs 530925/733680 to scan for vulnerable instances. Monitoring: Review web server logs for anomalous requests to admin-ajax.php and audit wp-content/uploads/ for unexpected PHP files.
Wordfence published the initial disclosure and noted that approximately 800,000 WordPress sites were affected, generating significant community attention (Wordfence). BleepingComputer and The Hacker News covered the vulnerability extensively, with BleepingComputer later reporting on the PCPJack worm's active exploitation of this CVE in cloud environments (BleepingComputer, The Hacker News). Security researchers on Reddit's r/WordpressPlugins and Infosec.exchange discussed the vulnerability's severity and the novel null-byte key bypass technique. SentinelOne's threat intelligence team published a detailed analysis of PCPJack's use of this CVE in worm-like cloud attacks, which was widely shared across the security community (SentinelOne).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."