VYPR

All-in-One WP Migration and Backup

by WordPress

CVEs (9)

  • CVE-2026-19949HigAug 25, 2026
    risk 0.57cvss 8.8epss 0.01

    The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via archive restore functionality in all versions up to, and including, 7.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…

  • CVE-2026-81810HigSep 18, 2026
    risk 0.47cvss 7.2epss 0.00

    The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability check on several of its AJAX actions, gating them only on an installation-wide secret which it discloses to any user permitted to export the site, allowing such a user to import…

  • CVE-2026-17533HigAug 16, 2026
    risk 0.47cvss 7.2epss 0.00

    The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import functionality to network administrators on multisite installations, allowing an administrator of a single subsite to execute arbitrary PHP code across the entire network.

  • CVE-2024-9162HigOct 28, 2024
    risk 0.47cvss 7.2epss 0.03

    The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to arbitrary PHP Code Injection due to missing file type validation during the export in all versions up to, and including, 7.86. This makes it possible for authenticated attackers, with…

  • CVE-2024-10942HigMar 13, 2025
    risk 0.42cvss 7.5epss 0.01

    The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.89 via deserialization of untrusted input in the 'replace_serialized_values' function. This makes it possible for unauthenticated attackers…

  • CVE-2024-8852MedOct 22, 2024
    risk 0.35cvss 5.3epss 0.01

    The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.86 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive…

  • CVE-2026-89064MedSep 17, 2026
    risk 0.34cvss 5.3epss 0.00

    The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Insufficient Credential Protection in versions up to, and including, 7.110. This is due to the `Ai1wm_Main_Controller::init()` method — registered on the `admin_init` hook, which fires unauthenticated…

  • CVE-2025-8490MedAug 27, 2025
    risk 0.29cvss 4.4epss 0.00

    The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Import in all versions up to, and including, 7.97 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2026-12898MedJul 20, 2026
    risk 0.00cvss 6.5epss 0.01

    The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file path, allowing unauthenticated attackers to create or append a log file in arbitrary locations outside its intended storage…