PT-2023-12789 · WordPress · All-In-One Wp Migration

Filipe Baptistella

+12

·

Publicado

2023-02-02

·

Atualizado

2025-03-26

·

CVE-2022-2546

CVSS v3.1

4.7

Média

VetorAV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions All-in-One WP Migration WordPress plugin versions prior to 7.63
Description The issue allows an attacker to craft a request that, when submitted by any visitor, will inject arbitrary HTML or JavaScript into the response, which will be executed in the victim's session. This requires knowledge of a static secret key. The problem arises from the wrong content type being used and the response from the ai1wm export AJAX action not being properly escaped.
Recommendations For versions prior to 7.63, update to version 7.63 or later to resolve the issue. As a temporary workaround, consider restricting access to the ai1wm export AJAX action until a patch is available. Avoid using the All-in-One WP Migration WordPress plugin with untrusted visitors until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2022-2546

Produtos afetados

All-In-One Wp Migration