Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Ploogins

Ploogins Vendor Cyber Rating & Cyber Score

ploogins.com

Snag the perfect WordPress plugins for your projects in a snap. Just whisper your needs to Ploogins, and voila! It'll hook you up with the crème de la crème from the sprawling universe of over 60,000 plugins in the official stash as well as commercial paid plugins from large or niche development companies. With Ploogins riding shotgun, web developers can turbocharge their workflow, delivering sleek, need-specific projects to their clients. Ploogins is the trailblazing WordPress plugin guru, juiced up by AI to master the art of semantic searches in plain English. Or Spanish. Or French. Or... whatever.


Ploogins A.I CyberSecurity Scoring

Ploogins
Company Information
Website:https://ploogins.com
Employees number:5
Number of followers:210
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:ploogins.com
Ploogins Risk Score (AI oriented)
Between 700 and 749
logo
PlooginsTechnology, Information and Internet
Updated:
10/03/2026
748/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Ploogins Global Score (TPRM)
xxxx
logo
PlooginsTechnology, Information and Internet
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Ploogins
PlooginsModerate
Current Score
748Ba (MODERATE)
01000
1 incidents
-17 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
749Before Incident
MAY 2026
749Before Incident
APRIL 2026
749Before Incident
MARCH 2026
748Before Incident
FEBRUARY 2026
748Before Incident
JANUARY 2026
765Before Incident
Vulnerability
22 Jan 2026Ploogins
WPvivid: WordPress Backup Plugin Vulnerability Exposes 800,000 Sites to Remote Code Execution Attacks

Critical RCE Vulnerability in WPvivid Backup Plugin Exposes 800,000+ WordPress Sites

748After Incident
CRITICAL-17
PLO1770889816
Critical RCE Vulnerability in WPvivid Backup Plugin Exposes 800,000+ WordPress Sites A severe remote code execution (RCE) vulnerability in the WPvivid Backup & Migration plugin tracked as CVE-2026-1357 (CVSS 9.8) has left over 800,000 WordPress websites vulnerable to complete takeover. The flaw, discovered by security researcher Lucas Montes (NiRoX) and reported via the Wordfence Bug Bounty Program, enables unauthenticated attackers to upload arbitrary files and execute malicious PHP code on affected sites. The vulnerability stems from improper error handling in the plugin’s RSA decryption process and missing file path sanitization. When decryption fails, the plugin passes a `false` value into the AES cipher initialization, which the crypto library interprets as a string of null bytes. This predictable key allows attackers to encrypt payloads and bypass security controls. Additionally, unsanitized filenames permit directory traversal, letting threat actors write files to publicly accessible locations outside the backup directory. Exploitation occurs via the `wpvivid_action=send_to_site` parameter, which attackers can abuse to upload and execute arbitrary PHP files, leading to full site compromise. While the most critical exposure affects sites with the remote backup feature enabled (disabled by default and limited to a 24-hour key lifetime), all unpatched installations remain at risk. The vendor, WPvivid, released a patch (version 0.9.124) on January 28, 2026, after being notified on January 22. The fix introduces an empty check for decryption failures and enforces strict file extension validation to block malicious uploads. Wordfence deployed a firewall rule for paid customers on January 22, with free users gaining protection on February 21, 2026. Montes received a $2,145 bounty for the disclosure, highlighting the role of bug bounty programs in improving WordPress plugin security. Site owners are advised to update to version 0.9.124 or later immediately to mitigate the risk.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Systems Affected: 800,000+ WordPress sitesOperational Impact: Full site compromise
DATA BREACH
File Types Exposed: PHP files
DECEMBER 2025
765Before Incident
NOVEMBER 2025
765Before Incident
OCTOBER 2025
765Before Incident
SEPTEMBER 2025
765Before Incident
AUGUST 2025
765Before Incident
JULY 2025
765Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Ploogins ?
?
What was Ploogins's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Ploogins's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Ploogins's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Ploogins's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Ploogins's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Ploogins's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Ploogins's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Ploogins's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Ploogins's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Ploogins's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Ploogins's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Ploogins's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Ploogins ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Ploogins's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?