PT-2023-12789 · WordPress · All-In-One Wp Migration

Filipe Baptistella

+12

·

Published

2023-02-02

·

Updated

2025-03-26

·

CVE-2022-2546

CVSS v3.1

4.7

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions All-in-One WP Migration WordPress plugin versions prior to 7.63
Description The issue allows an attacker to craft a request that, when submitted by any visitor, will inject arbitrary HTML or JavaScript into the response, which will be executed in the victim's session. This requires knowledge of a static secret key. The problem arises from the wrong content type being used and the response from the ai1wm export AJAX action not being properly escaped.
Recommendations For versions prior to 7.63, update to version 7.63 or later to resolve the issue. As a temporary workaround, consider restricting access to the ai1wm export AJAX action until a patch is available. Avoid using the All-in-One WP Migration WordPress plugin with untrusted visitors until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-2546

Affected Products

All-In-One Wp Migration