PT-2026-95232 · WordPress · All-In-One Wp Migration/Backup

·

CVE-2026-81810

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions All-in-One WP Migration and Backup WordPress plugin versions prior to 7.111
Description Several AJAX actions do not perform proper capability checks and are instead protected by an installation-wide secret. This secret is disclosed to any user with permission to export the site. Consequently, a user with export privileges can import an arbitrary site archive to gain administrator access. This issue occurs when an administrator grants export capabilities to a role that lacks the plugin's native import capability, which is not the default configuration.
Recommendations Update to version 7.111 or later.

Exploit

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81810

Affected Products

All-In-One Wp Migration/Backup