PT-2025-11168 · WordPress · All-In-One Wp Migration/Backup

Craig Smith

+1

·

Published

2025-03-13

·

Updated

2025-03-18

·

CVE-2024-10942

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: All-in-One WP Migration and Backup plugin for WordPress versions up to, and including, 7.89
Description: The issue allows unauthenticated attackers to inject a PHP Object via deserialization of untrusted input in the replace serialized values function. If a POP chain is present, possibly through an additional plugin or theme, it could enable the attacker to delete arbitrary files, retrieve sensitive data, or execute code. The exploit can be triggered by an administrator exporting and restoring a backup.
Recommendations: For versions up to, and including, 7.89, update to a version that fixes the PHP Object Injection issue to prevent exploitation. As a temporary workaround, consider restricting access to the replace serialized values function until a patch is available.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-10942

Affected Products

All-In-One Wp Migration/Backup