All verified exploits

CVE-2026-1357 WPvivid File Upload via Crypto Fail-Open

Deterministic critical WordPress Added cve-verified-cve-2026-1357

Exploits a cryptographic fail-open in the WPvivid Backup & Migration plugin's backup transfer feature. When RSA decryption fails, the plugin falls back to a null AES key, allowing an attacker to encrypt a payload with that null key and upload arbitrary files via path traversal. We upload a harmless canary file to prove the flaw exists.

Related WordPress exploits

Is your app exploitable through CVE-2026-1357?

Scan your domain free