plugin

All In One Wp Migration Vulnerabilities

35 known security issues reported for the All In One Wp Migration WordPress plugin. Most recent disclosed Aug 24, 2026.

7 high 9 medium

Running All In One Wp Migration on your site? Check whether your installed version is affected.

Scan your site free

All-in-One WP Migration and Backup <= 7.109 - Unauthenticated Second-Order SQL Injection via Archive Restore to Remote Code Execution

high

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via archive restore functionality in all versions up to, and including, 7.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for un...

CVSS:
8.8
Affected:
up to 7.109
Fixed in:
7.110
Disclosed:
Aug 24, 2026

CVE-2026-19949 on NVD →

All-in-One WP Migration and Backup < 7.108 - Authenticated (Administrator+) Remote Code Execution

high

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 7.108. This is due to insufficient validation of user supplied input before it is executed. This makes it possible for authenticated attackers, with administrator-level access and above, to execute a...

CVSS:
7.2
Affected:
up to 7.108
Fixed in:
7.108
Disclosed:
Aug 20, 2026

CVE-2026-17533 on NVD →

All-in-One WP Migration and Backup <= 7.105 - Missing Authorization

medium

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.105. This makes it possible for unauthenticated attackers to write logs to an arbitrary location.

CVSS:
5.3
Affected:
up to 7.105
Fixed in:
7.106
Disclosed:
Jun 29, 2026

CVE-2026-12898 on NVD →

All-in-One WP Migration and Backup <= 7.97 - Authenticated (Administrator+) Stored Cross-Site Scripting via Import

medium

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Import in all versions up to, and including, 7.97 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject ar...

CVSS:
4.4
Affected:
up to 7.97
Fixed in:
7.98
Disclosed:
Aug 26, 2025

CVE-2025-8490 on NVD →

All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.90

unknown

[en] The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.89 via deserialization of untrusted input in the 'replace_serialized_values' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP...

Affected:
up to 7.90
Fixed in:
7.90
Disclosed:
Mar 13, 2025

CVE-2024-10942 on NVD →

All in One WP Migration <= 7.89 - Unauthenticated PHP Object Injection

high

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.89 via deserialization of untrusted input in the 'replace_serialized_values' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain...

CVSS:
7.5
Affected:
up to 7.89
Fixed in:
7.90
Disclosed:
Mar 12, 2025

CVE-2024-10942 on NVD →

All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.87

unknown

[en] The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to arbitrary PHP Code Injection due to missing file type validation during the export in all versions up to, and including, 7.86. This makes it possible for authenticated attackers, with Administrator-level access and above, to create an exp...

Affected:
up to 7.87
Fixed in:
7.87
Disclosed:
Oct 28, 2024

CVE-2024-9162 on NVD →

All-in-One WP Migration and Backup <= 7.86 - Authenticated (Administrator+) Arbitrary PHP Code Injection

high

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to arbitrary PHP Code Injection due to missing file type validation during the export in all versions up to, and including, 7.86. This makes it possible for authenticated attackers, with Administrator-level access and above, to create an export f...

CVSS:
7.2
Affected:
up to 7.86
Fixed in:
7.87
Disclosed:
Oct 27, 2024

CVE-2024-9162 on NVD →

All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.87

unknown

[en] The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.86 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information such as full paths contained in t...

Affected:
up to 7.87
Fixed in:
7.87
Disclosed:
Oct 22, 2024

CVE-2024-8852 on NVD →

All-in-One WP Migration and Backup <= 7.86 - Unauthenticated Information Disclosure via Error Logs

medium

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.86 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information such as full paths contained in the ex...

CVSS:
5.3
Affected:
up to 7.86
Fixed in:
7.87
Disclosed:
Oct 21, 2024

CVE-2024-8852 on NVD →

All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.63

unknown

[en] The All-in-One WP Migration WordPress plugin before 7.63 uses the wrong content type, and does not properly escape the response from the ai1wm_export AJAX action, allowing an attacker to craft a request that when submitted by any visitor will inject arbitrary html or javascript into the response that will be execu...

Affected:
up to 7.63
Fixed in:
7.63
Disclosed:
Feb 2, 2023

CVE-2022-2546 on NVD →

All-in-One WP Migration <= 7.62 - Unauthenticated Reflected Cross-Site Scripting

medium

The All-in-One WP Migration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.62 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...

CVSS:
6.1
Affected:
up to 7.62
Fixed in:
7.63
Disclosed:
Aug 23, 2022

CVE-2022-2546 on NVD →

All-in-One WP Migration <= 7.62 - Authenticated (Admin+) Cross-Site Scripting

medium

The All-in-One WP Migration plugin for WordPress is vulnerable to cross-site scripting via the 'storage' parameter in versions up to, and including, 7.62 due to insufficient input sanitization and output escaping. This allows attackers to execute arbitrary web scripts in victim's browsers. This only affects multi-site...

CVSS:
5.5
Affected:
up to 7.62
Fixed in:
7.63
Disclosed:
Aug 15, 2022

All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.63

unknown

The All-in-One WP Migration plugin for WordPress is vulnerable to cross-site scripting via the 'storage' parameter in versions up to, and including, 7.62 due to insufficient input sanitization and output escaping. This allows attackers to execute arbitrary web scripts in victim's browsers. This only affects multi-site...

Affected:
up to 7.63
Fixed in:
7.63
Disclosed:
Aug 15, 2022

All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.59

unknown

[en] The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to insufficient file validation via the ~/lib/model/class-ai1wm-backups.php file, in versions up to, and including, 7.58. This can be exploited by administrative users, and users who have access to...

Affected:
up to 7.59
Fixed in:
7.59
Disclosed:
May 10, 2022

CVE-2022-1476 on NVD →

All-in-One WP Migration <= 7.58 - Directory Traversal to File Deletion on Windows Hosts

medium

The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to insufficient file validation via the ~/lib/model/class-ai1wm-backups.php file, in versions up to, and including, 7.58. This can be exploited by administrative users, and users who have access to the...

CVSS:
6.6
Affected:
up to 7.58
Fixed in:
7.59
Disclosed:
Apr 28, 2022

CVE-2022-1476 on NVD →

All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.41

unknown

[en] The All-in-One WP Migration WordPress plugin before 7.41 does not validate uploaded files' extension, which allows administrators to upload PHP files on their site, even on multisite installations.

Affected:
up to 7.41
Fixed in:
7.41
Disclosed:
Mar 7, 2022

CVE-2021-24216 on NVD →

All-in-One WP Migration <= 7.40 - Authenticated (Admin+) Arbitrary File Upload

high

The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on file upload in versions up to, and including, 7.40. This makes it possible for authenticated attackers with administrative privileges to upload arbitrary files on the affected sites server whi...

CVSS:
7.2
Affected:
up to 7.40
Fixed in:
7.41
Disclosed:
Feb 7, 2022

CVE-2021-24216 on NVD →

All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.15

unknown

Arbitrary Backup Download vulnerability found by Kamil Vavra in WordPress All-in-One WP Migration plugin (versions <= 7.14).

Affected:
up to 7.15
Fixed in:
7.15
Disclosed:
Mar 25, 2020

All-in-One WP Migration <= 7.14 - Unauthenticated Backup Download

medium

The All-in-One WP Migration plugin for WordPress is vulnerable to unauthenticated arbitrary back-up downloads due to insufficient filename randomization that made it possible for unauthenticated attackers to brute force back-up filenames in unique situations in versions up to, and including, 7.14. This would make it po...

CVSS:
5.9
Affected:
up to 7.15
Fixed in:
7.15
Disclosed:
Jan 20, 2020

All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.15

unknown

The All-in-One WP Migration plugin for WordPress is vulnerable to unauthenticated arbitrary back-up downloads due to insufficient filename randomization that made it possible for unauthenticated attackers to brute force back-up filenames in unique situations in versions up to, and including, 7.14. This would make it po...

Affected:
up to 7.15
Fixed in:
7.15
Disclosed:
Jan 20, 2020

All-in-One WP Migration <= 6.97 - Authenticated Stored Cross-Site Scripting

medium

The All-in-One WP Migration plugin for WordPress is vulnerable to Cross-Site Scripting due to the fact that the backup description on the backup history overview page does not sanitize/escape html entities when generating the input field.

CVSS:
5.5
Affected:
up to 7.0
Fixed in:
7.0
Disclosed:
Jul 18, 2019

All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.0

unknown

The All-in-One WP Migration plugin for WordPress is vulnerable to Cross-Site Scripting due to the fact that the backup description on the backup history overview page does not sanitize/escape html entities when generating the input field.

Affected:
up to 7.0
Fixed in:
7.0
Disclosed:
Jul 18, 2019

All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.0

unknown

Cross-Site Scripting (XSS) vulnerability (admin backend) found by Connum in WordPress All-in-One WP Migration plugin (versions <= 6.97).

Affected:
up to 7.0
Fixed in:
7.0
Disclosed:
Jul 18, 2019

All-in-One WP Migration <= 6.45 - Reflected Cross-Site Scripting

medium

The All-in-One WP Migration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘secret_key’ parameter in versions up to, and including, 6.45 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

CVSS:
6.1
Affected:
up to 6.46
Fixed in:
6.46
Disclosed:
Jun 20, 2017

All-in-One WP Migration and Backup [all-in-one-wp-migration] < 6.46

unknown

The All-in-One WP Migration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘secret_key’ parameter in versions up to, and including, 6.45 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

Affected:
up to 6.46
Fixed in:
6.46
Disclosed:
Jun 20, 2017

All-in-One WP Migration <= 2.0.4 - Missing Authorization to Database Export

high

The All-in-One WP Migration plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'router()' function in versions up to, and including, 2.0.4. This makes it possible for unauthenticated attackers to export a complete copy of the vulnerable service's database.

CVSS:
7.5
Affected:
up to 2.0.4
Fixed in:
2.0.5
Disclosed:
Mar 19, 2015

All-in-One WP Migration and Backup [all-in-one-wp-migration] < 2.0.5

unknown

The All-in-One WP Migration plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'router()' function in versions up to, and including, 2.0.4. This makes it possible for unauthenticated attackers to export a complete copy of the vulnerable service's database.

Affected:
up to 2.0.5
Fixed in:
2.0.5
Disclosed:
Mar 19, 2015

All-in-One WP Migration and Backup [all-in-one-wp-migration] < 2.0.5

unknown

Because of this vulnerability, users, which have access to the database, can get uploads, themes, plugins of your website. Update the plugin.

Affected:
up to 2.0.5
Fixed in:
2.0.5
Disclosed:
Mar 19, 2015

All-in-One WP Migration <= 2.0.2 - Authorization Bypass to Arbitrary File Upload

high

The All-in-One WP Migration plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the import() function in versions up to, and including, 2.0.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to upload arbitrary files.

CVSS:
8.8
Affected:
up to 2.0.2
Fixed in:
2.0.3
Disclosed:
Nov 5, 2014

All-in-One WP Migration and Backup [all-in-one-wp-migration] < 2.0.3

unknown

The All-in-One WP Migration plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the import() function in versions up to, and including, 2.0.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to upload arbitrary files.

Affected:
up to 2.0.3
Fixed in:
2.0.3
Disclosed:
Nov 5, 2014

All-in-One WP Migration and Backup [all-in-one-wp-migration] < 2.0.5

unknown

Unauthenticated users can export a complete copy of the WordPress database, all plugins, themes, and uploaded files.

Affected:
up to 2.0.5
Fixed in:
2.0.5

All-in-One WP Migration and Backup [all-in-one-wp-migration] < 6.46

unknown

All-in-One WP Migration is vulnerable to Reflected Cross-Site Scripting on secret_key parameter.

Affected:
up to 6.46
Fixed in:
6.46

All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.0

unknown

An attacker would already have to be able to either compromise the database or gain access to a user account with high enough privileges to view the backup history, so some damage has already been done, but such an attacker could then also insert some XSS in order to compromise other admin users. When double-clickin...

Affected:
up to 7.0
Fixed in:
7.0

All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.15

unknown

Lack of randomness in the backup filenames could allow unauthenticated attackers to guess and download them

Affected:
up to 7.15
Fixed in:
7.15

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database