sales@hackhalt.com

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total4
Critical0
High2
Medium2
Reset
Showing 1-4 of 4 records
Threat Entry Updated 2026-09-18

All-in-One WP Migration and Backup - Security Vulnerability (CVE-2026-81810)

The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability check on several of its AJAX actions, gating them only on an installation-wide secret which it discloses to any user permitted to export the site, allowing such a user to import an arbitrary site archive and gain administrator access. Exploitation requires an administrator to have granted the export capability to a role that does not hold the All-in-One WP Migration and Backup WordPress plugin before 7.111's own import capability, which is not a default configuration.

PLUGIN All-in-One WP Migration and Backup

CVE-2026-81810

HIGH CVSS 7.2 2026-09-18
Threat Entry Updated 2026-09-18

All-in-One WP Migration and Backup - Security Vulnerability (CVE-2026-89064)

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Insufficient Credential Protection in versions up to, and including, 7.110. This is due to the `Ai1wm_Main_Controller::init()` method — registered on the `admin_init` hook, which fires unauthenticated on `admin-ajax.php` and `admin-post.php` requests — reading `$_SERVER['PHP_AUTH_USER']` and `$_SERVER['PHP_AUTH_PW']` from any incoming request and writing them to the `ai1wm_auth_header` option via `update_option()` as a reversible base64-encoded string, with no capability check, nonce verification, `is_user_logged_in()` check, or confirmation that Basic authentication actually succeeded. This makes it possible for unauthenticated attackers to capture…

PLUGIN All-in-One WP Migration and Backup

CVE-2026-89064

MEDIUM CVSS 5.3 2026-09-17
Threat Entry Updated 2026-08-26

All-in-One WP Migration and Backup - Security Vulnerability (CVE-2026-17533)

The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import functionality to network administrators on multisite installations, allowing an administrator of a single subsite to execute arbitrary PHP code across the entire network.

PLUGIN All-in-One WP Migration and Backup

CVE-2026-17533

HIGH CVSS 7.2 2026-08-16
Threat Entry Updated 2026-07-20

All-in-One WP Migration and Backup - Security Vulnerability (CVE-2026-12898)

The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file path, allowing unauthenticated attackers to create or append a log file in arbitrary locations outside its intended storage directory.

PLUGIN All-in-One WP Migration and Backup

CVE-2026-12898

MEDIUM CVSS 6.5 2026-07-20