VYPR

All-in-One WP Migration and Backup

by WordPress

CVEs (6)

  • CVE-2026-17533HigAug 16, 2026
    risk 0.47cvss 7.2epss 0.00

    The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import functionality to network administrators on multisite installations, allowing an administrator of a single subsite to execute arbitrary PHP code across the entire network.

  • CVE-2024-9162HigOct 28, 2024
    risk 0.47cvss 7.2epss 0.03

    The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to arbitrary PHP Code Injection due to missing file type validation during the export in all versions up to, and including, 7.86. This makes it possible for authenticated attackers, with…

  • CVE-2024-10942HigMar 13, 2025
    risk 0.42cvss 7.5epss 0.01

    The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.89 via deserialization of untrusted input in the 'replace_serialized_values' function. This makes it possible for unauthenticated attackers…

  • CVE-2024-8852MedOct 22, 2024
    risk 0.35cvss 5.3epss 0.01

    The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.86 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive…

  • CVE-2025-8490MedAug 27, 2025
    risk 0.29cvss 4.4epss 0.00

    The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Import in all versions up to, and including, 7.97 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2026-12898MedJul 20, 2026
    risk 0.00cvss 6.5epss 0.00

    The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file path, allowing unauthenticated attackers to create or append a log file in arbitrary locations outside its intended storage…