CVE-2025-5961 affects the Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress. In all versions up to and including 0.9.116, the plugin's 'wpvivid_upload_import_files' function does not properly validate uploaded file types, allowing arbitrary file upload. An authenticated attacker with Administrator-level privileges or higher can upload attacker-controlled files to the server. On affected WordPress deployments running under NGINX, those uploaded files may be directly accessible and can potentially be executed, resulting in remote code execution. On Apache deployments, an existing .htaccess file in the upload directory is noted as preventing direct access to uploaded files.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Python exploit script targeting CVE-2025-5961, a vulnerability in the WPvivid Backup & Migration WordPress plugin (versions 0.9.116 and below). The exploit requires administrator credentials for the target WordPress site. The script performs the following steps: (1) checks the plugin version by fetching its readme.txt, (2) logs in as the provided admin user, (3) extracts a required nonce from the plugin's admin page, (4) uploads a PHP web shell via a vulnerable AJAX endpoint, and (5) prints the URL to access the shell, which allows arbitrary command execution via the 'cmd' parameter. The repository includes the main exploit script (CVE-2025-5961.py), a README with usage instructions and vulnerability details, a requirements.txt for dependencies, and a license file. The exploit is operational and provides a working web shell if the target is vulnerable and valid credentials are supplied.
This repository contains a working exploit for CVE-2025-5961, targeting the WPvivid Backup & Migration WordPress plugin (<= 0.9.116). The exploit is implemented in a single Python script (CVE-2025-5961.py) and is accompanied by a detailed README.md. The exploit requires valid WordPress administrator credentials and targets the plugin's 'wpvivid_upload_import_files' action, which fails to properly validate file types. The script logs into the WordPress admin panel, extracts a required AJAX nonce, and uploads a PHP web shell ('hack.php') to a predictable location on the server. The shell allows arbitrary command execution via the 'cmd' GET parameter. The README provides step-by-step manual exploitation instructions and highlights that the attack is only effective on NGINX servers, as Apache's .htaccess blocks access to the uploaded shell. The repository is well-structured, with clear documentation and a functional exploit script. No detection scripts or framework integration are present; this is a standalone operational exploit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.