Security
CVE-2026-1357: WPvivid Backup Plugin Flaw Lets Attackers Upload Webshells Without Logging In
CVE-2026-1357 is a 9.8-rated unauthenticated remote code execution vulnerability in the WPvivid Backup & Migration plugin, installed on roughly 800,000 WordPress sites. An attacker can write a PHP webshell to a publicly accessible directory — no account, no credentials, one HTTP request. From there it'