PT-2026-73119 · WordPress · All-In-One Wp Migration/Backup
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
All-in-One WP Migration and Backup WordPress plugin versions prior to 7.108
Description
On multisite installations, the migration import functionality is not restricted to network administrators. This allows an administrator of a single subsite to execute arbitrary PHP code across the entire network. PHP is a server-side scripting language used primarily for web development.
Recommendations
Update the plugin to version 7.108 or later.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
All-In-One Wp Migration/Backup