PT-2024-39276 · WordPress · All-In-One Wp Migration/Backup

Villu Orav

+1

·

Published

2024-10-22

·

Updated

2026-04-14

·

CVE-2024-8852

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: All-in-One WP Migration and Backup plugin for WordPress versions up to, and including, 7.86
Description: The issue allows unauthenticated attackers to view potentially sensitive information, such as full paths, contained in publicly exposed log files. This is possible due to Sensitive Information Exposure in the plugin.
Recommendations: For versions up to, and including, 7.86, update to a version that fixes the Sensitive Information Exposure issue to prevent unauthenticated attackers from viewing sensitive information. As a temporary workaround, consider restricting access to the publicly exposed log files until a patch is available.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-8852

Affected Products

All-In-One Wp Migration/Backup