Ploogins A.I CyberSecurity Scoring
Ploogins
Company Information
Website:https://ploogins.com
Employees number:5
Number of followers:210
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:ploogins.com
Ploogins Risk Score (AI oriented)
Between 700 and 749
PlooginsTechnology, Information and Internet
Updated:
10/03/2026
10/03/2026
748/1000
Moderate
Ba
Ploogins Global Score (TPRM)
xxxx
PlooginsTechnology, Information and Internet
Score locked

PlooginsModerate
Current Score
748Ba (MODERATE)
01000
1 incidents
-17 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
749
MAY 2026
749
APRIL 2026
749
MARCH 2026
748
FEBRUARY 2026
748
JANUARY 2026
765
Vulnerability
22 Jan 2026 • Ploogins
WPvivid: WordPress Backup Plugin Vulnerability Exposes 800,000 Sites to Remote Code Execution Attacks
Critical RCE Vulnerability in WPvivid Backup Plugin Exposes 800,000+ WordPress Sites
748
CRITICAL-17
PLO1770889816
Critical RCE Vulnerability in WPvivid Backup Plugin Exposes 800,000+ WordPress Sites
A severe remote code execution (RCE) vulnerability in the WPvivid Backup & Migration plugin tracked as CVE-2026-1357 (CVSS 9.8) has left over 800,000 WordPress websites vulnerable to complete takeover. The flaw, discovered by security researcher Lucas Montes (NiRoX) and reported via the Wordfence Bug Bounty Program, enables unauthenticated attackers to upload arbitrary files and execute malicious PHP code on affected sites.
The vulnerability stems from improper error handling in the plugin’s RSA decryption process and missing file path sanitization. When decryption fails, the plugin passes a `false` value into the AES cipher initialization, which the crypto library interprets as a string of null bytes. This predictable key allows attackers to encrypt payloads and bypass security controls. Additionally, unsanitized filenames permit directory traversal, letting threat actors write files to publicly accessible locations outside the backup directory.
Exploitation occurs via the `wpvivid_action=send_to_site` parameter, which attackers can abuse to upload and execute arbitrary PHP files, leading to full site compromise. While the most critical exposure affects sites with the remote backup feature enabled (disabled by default and limited to a 24-hour key lifetime), all unpatched installations remain at risk.
The vendor, WPvivid, released a patch (version 0.9.124) on January 28, 2026, after being notified on January 22. The fix introduces an empty check for decryption failures and enforces strict file extension validation to block malicious uploads. Wordfence deployed a firewall rule for paid customers on January 22, with free users gaining protection on February 21, 2026.
Montes received a $2,145 bounty for the disclosure, highlighting the role of bug bounty programs in improving WordPress plugin security. Site owners are advised to update to version 0.9.124 or later immediately to mitigate the risk.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
765
NOVEMBER 2025
765
OCTOBER 2025
765
SEPTEMBER 2025
765
AUGUST 2025
765
JULY 2025
765
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Ploogins ??
What was Ploogins's A.I Rankiteo Cyber Score in May 2026 ??
What was Ploogins's A.I Rankiteo Cyber Score in April 2026 ??
What was Ploogins's A.I Rankiteo Cyber Score in March 2026 ??
What was Ploogins's A.I Rankiteo Cyber Score in February 2026 ??
What was Ploogins's A.I Rankiteo Cyber Score in January 2026 ??
What was Ploogins's A.I Rankiteo Cyber Score in December 2025 ??
What was Ploogins's A.I Rankiteo Cyber Score in November 2025 ??
What was Ploogins's A.I Rankiteo Cyber Score in October 2025 ??
What was Ploogins's A.I Rankiteo Cyber Score in September 2025 ??
What was Ploogins's A.I Rankiteo Cyber Score in August 2025 ??
What was Ploogins's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Ploogins's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Ploogins ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Ploogins's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?