PT-2026-94137 · WordPress · All-In-One Wp Migration/Backup
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
All-in-One WP Migration and Backup versions prior to 7.111
Description
The plugin contains an issue related to insufficient credential protection. The
Ai1wm Main Controller::init() function, which is registered on the admin init hook and executes without authentication on admin-ajax.php and admin-post.php requests, reads the $ SERVER['PHP AUTH USER'] and $ SERVER['PHP AUTH PW'] variables from incoming requests. These values are then written to the ai1wm auth header option using the update option() function as reversible base64-encoded strings. This process occurs without capability checks, nonce verification, or confirmation of successful Basic authentication. Consequently, unauthenticated attackers can capture WordPress Application Passwords or HTTP Basic credentials used by legitimate integrations in the database or overwrite stored credentials by sending a request with a crafted Authorization: Basic header to the /wp-admin/ endpoint. This is especially critical for environments utilizing WordPress Application Passwords for REST API or third-party integrations.Recommendations
Update All-in-One WP Migration and Backup to a version later than 7.110.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
All-In-One Wp Migration/Backup