PT-2023-12789 · WordPress · All-In-One Wp Migration
Filipe Baptistella
+12
·
Published
2023-02-02
·
Updated
2025-03-26
·
CVE-2022-2546
CVSS v3.1
4.7
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
All-in-One WP Migration WordPress plugin versions prior to 7.63
Description
The issue allows an attacker to craft a request that, when submitted by any visitor, will inject arbitrary HTML or JavaScript into the response, which will be executed in the victim's session. This requires knowledge of a static secret key. The problem arises from the wrong content type being used and the response from the
ai1wm export AJAX action not being properly escaped.Recommendations
For versions prior to 7.63, update to version 7.63 or later to resolve the issue. As a temporary workaround, consider restricting access to the
ai1wm export AJAX action until a patch is available. Avoid using the All-in-One WP Migration WordPress plugin with untrusted visitors until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
All-In-One Wp Migration