PT-2026-94137 · WordPress · All-In-One Wp Migration/Backup

·

CVE-2026-89064

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions All-in-One WP Migration and Backup versions prior to 7.111
Description The plugin contains an issue related to insufficient credential protection. The Ai1wm Main Controller::init() function, which is registered on the admin init hook and executes without authentication on admin-ajax.php and admin-post.php requests, reads the $ SERVER['PHP AUTH USER'] and $ SERVER['PHP AUTH PW'] variables from incoming requests. These values are then written to the ai1wm auth header option using the update option() function as reversible base64-encoded strings. This process occurs without capability checks, nonce verification, or confirmation of successful Basic authentication. Consequently, unauthenticated attackers can capture WordPress Application Passwords or HTTP Basic credentials used by legitimate integrations in the database or overwrite stored credentials by sending a request with a crafted Authorization: Basic header to the /wp-admin/ endpoint. This is especially critical for environments utilizing WordPress Application Passwords for REST API or third-party integrations.
Recommendations Update All-in-One WP Migration and Backup to a version later than 7.110.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-89064

Affected Products

All-In-One Wp Migration/Backup