Medium severity6.6NVD Advisory· Published May 10, 2022· Updated Apr 8, 2026
CVE-2022-1476
CVE-2022-1476
Description
The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to insufficient file validation via the ~/lib/model/class-ai1wm-backups.php file, in versions up to, and including, 7.58. This can be exploited by administrative users, and users who have access to the site's secret key.
Affected products
1- cpe:2.3:a:servmask:all-in-one_wp_migration:*:*:*:*:*:wordpress:*:*Range: <=7.58
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- plugins.trac.wordpress.org/changesetnvdPatchThird Party Advisory
- www.wordfence.com/vulnerability-advisories/nvdThird Party Advisory
- www.wordfence.com/threat-intel/vulnerabilities/id/e58634c3-7fcd-4885-b897-4e6a97fb06acnvd
News mentions
0No linked articles in our index yet.