Extension WordPress
Vulnérabilités All-in-One WP Migration and Backup
Cette page rassemble les failles publiées pour All-in-One WP Migration and Backup, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de All-in-One WP Migration and Backup
13 fiches
All-in-One WP Migration and Backup <= 7.97 – Authenticated (Administrator+) Stored Cross-Site Scripting via Import
The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Import in all versions up to, and including, 7.97 due to insufficient input sanitization and output escaping. This makes it possible…
*-7.97
7.98
26/08/2025
All in One WP Migration <= 7.89 – Unauthenticated PHP Object Injection
The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.89 via deserialization of untrusted input in the 'replace_serialized_values' function. This makes it possible for unauthenticated…
*-7.89
7.90
12/03/2025
All-in-One WP Migration and Backup <= 7.86 – Authenticated (Administrator+) Arbitrary PHP Code Injection
The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to arbitrary PHP Code Injection due to missing file type validation during the export in all versions up to, and including, 7.86. This makes it possible for…
*-7.86
7.87
27/10/2024
All-in-One WP Migration and Backup <= 7.86 – Unauthenticated Information Disclosure via Error Logs
The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.86 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially…
*-7.86
7.87
21/10/2024
All-in-One WP Migration <= 7.62 – Unauthenticated Reflected Cross-Site Scripting
The All-in-One WP Migration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.62 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
*-7.62
7.63
23/08/2022
All-in-One WP Migration <= 7.62 – Authenticated (Admin+) Cross-Site Scripting
The All-in-One WP Migration plugin for WordPress is vulnerable to cross-site scripting via the 'storage' parameter in versions up to, and including, 7.62 due to insufficient input sanitization and output escaping. This allows attackers to execute arbitrary web…
*-7.62
7.63
15/08/2022
All-in-One WP Migration <= 7.58 – Directory Traversal to File Deletion on Windows Hosts
The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to insufficient file validation via the ~/lib/model/class-ai1wm-backups.php file, in versions up to, and including, 7.58. This can be exploited by administrative…
*-7.58
7.59
28/04/2022
All-in-One WP Migration <= 7.40 – Authenticated (Admin+) Arbitrary File Upload
The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on file upload in versions up to, and including, 7.40. This makes it possible for authenticated attackers with administrative…
*-7.40
7.41
07/02/2022
All-in-One WP Migration <= 7.14 – Unauthenticated Backup Download
The All-in-One WP Migration plugin for WordPress is vulnerable to unauthenticated arbitrary back-up downloads due to insufficient filename randomization that made it possible for unauthenticated attackers to brute force back-up filenames in unique situations in versions up to,…
[*, 7.15)
7.15
20/01/2020
All-in-One WP Migration <= 6.97 – Authenticated Stored Cross-Site Scripting
The All-in-One WP Migration plugin for WordPress is vulnerable to Cross-Site Scripting due to the fact that the backup description on the backup history overview page does not sanitize/escape html entities when generating the input field.
[*, 7.0)
7.0
18/07/2019
All-in-One WP Migration <= 6.45 – Reflected Cross-Site Scripting
The All-in-One WP Migration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘secret_key’ parameter in versions up to, and including, 6.45 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
[*, 6.46)
6.46
20/06/2017
All-in-One WP Migration <= 2.0.4 – Missing Authorization to Database Export
The All-in-One WP Migration plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'router()' function in versions up to, and including, 2.0.4. This makes it possible for unauthenticated attackers to export…
*-2.0.4
2.0.5
19/03/2015
All-in-One WP Migration <= 2.0.2 – Authorization Bypass to Arbitrary File Upload
The All-in-One WP Migration plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the import() function in versions up to, and including, 2.0.2. This makes it possible for authenticated attackers, with subscriber-level…
*-2.0.2
2.0.3
05/11/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.