Extension WordPress

Vulnérabilités All-in-One WP Migration and Backup

Cette page rassemble les failles publiées pour All-in-One WP Migration and Backup, leurs plages de versions affectées et les correctifs signalés dans la base locale.

13Vulnérabilités
0Critiques
13Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de All-in-One WP Migration and Backup

13 fiches

CVE-2025-8490 Moyenne · 4,4
All-in-One WP Migration and Backup

All-in-One WP Migration and Backup <= 7.97 – Authenticated (Administrator+) Stored Cross-Site Scripting via Import

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Import in all versions up to, and including, 7.97 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-7.97

Correctif

7.98

Publication

26/08/2025

CVE-2024-10942 Élevée · 7,5
All-in-One WP Migration and Backup

All in One WP Migration <= 7.89 – Unauthenticated PHP Object Injection

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.89 via deserialization of untrusted input in the 'replace_serialized_values' function. This makes it possible for unauthenticated…

Versions affectées

*-7.89

Correctif

7.90

Publication

12/03/2025

CVE-2024-8852 Moyenne · 5,3
All-in-One WP Migration and Backup

All-in-One WP Migration and Backup <= 7.86 – Unauthenticated Information Disclosure via Error Logs

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.86 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially…

Versions affectées

*-7.86

Correctif

7.87

Publication

21/10/2024

CVE-2022-2546 Moyenne · 6,1
All-in-One WP Migration and Backup

All-in-One WP Migration <= 7.62 – Unauthenticated Reflected Cross-Site Scripting

The All-in-One WP Migration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.62 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…

Versions affectées

*-7.62

Correctif

7.63

Publication

23/08/2022

Vulnérabilité Moyenne · 5,5
All-in-One WP Migration and Backup

All-in-One WP Migration <= 7.62 – Authenticated (Admin+) Cross-Site Scripting

The All-in-One WP Migration plugin for WordPress is vulnerable to cross-site scripting via the 'storage' parameter in versions up to, and including, 7.62 due to insufficient input sanitization and output escaping. This allows attackers to execute arbitrary web…

Versions affectées

*-7.62

Correctif

7.63

Publication

15/08/2022

CVE-2022-1476 Moyenne · 6,6
All-in-One WP Migration and Backup

All-in-One WP Migration <= 7.58 – Directory Traversal to File Deletion on Windows Hosts

The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to insufficient file validation via the ~/lib/model/class-ai1wm-backups.php file, in versions up to, and including, 7.58. This can be exploited by administrative…

Versions affectées

*-7.58

Correctif

7.59

Publication

28/04/2022

Vulnérabilité Moyenne · 5,9
All-in-One WP Migration and Backup

All-in-One WP Migration <= 7.14 – Unauthenticated Backup Download

The All-in-One WP Migration plugin for WordPress is vulnerable to unauthenticated arbitrary back-up downloads due to insufficient filename randomization that made it possible for unauthenticated attackers to brute force back-up filenames in unique situations in versions up to,…

Versions affectées

[*, 7.15)

Correctif

7.15

Publication

20/01/2020

Vulnérabilité Moyenne · 6,1
All-in-One WP Migration and Backup

All-in-One WP Migration <= 6.45 – Reflected Cross-Site Scripting

The All-in-One WP Migration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘secret_key’ parameter in versions up to, and including, 6.45 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

Versions affectées

[*, 6.46)

Correctif

6.46

Publication

20/06/2017

Vulnérabilité Élevée · 8,8
All-in-One WP Migration and Backup

All-in-One WP Migration <= 2.0.2 – Authorization Bypass to Arbitrary File Upload

The All-in-One WP Migration plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the import() function in versions up to, and including, 2.0.2. This makes it possible for authenticated attackers, with subscriber-level…

Versions affectées

*-2.0.2

Correctif

2.0.3

Publication

05/11/2014

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités