PT-2026-37342 · WordPress · All-In-One Wp Migration Unlimited Extension

Sélim Lanouar

·

Published

2026-05-06

·

Updated

2026-05-06

·

CVE-2026-5753

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions All-in-One WP Migration Unlimited Extension versions prior to 2.84
Description The plugin is affected by missing authorization. The Ai1wmve Schedules Controller::save function for the 'admin post ai1wm schedule event save' endpoint does not verify user capabilities before saving schedule data. This allows authenticated attackers with subscriber-level access or higher to create scheduled export jobs and direct backup notifications to email addresses they control. Since these notifications contain the random backup filename, attackers can download full site backups, leading to the exposure of sensitive information.
Recommendations Update to a version later than 2.83.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5753

Affected Products

All-In-One Wp Migration Unlimited Extension