PT-2026-37342 · WordPress · All-In-One Wp Migration Unlimited Extension
Sélim Lanouar
·
Published
2026-05-06
·
Updated
2026-05-06
·
CVE-2026-5753
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
All-in-One WP Migration Unlimited Extension versions prior to 2.84
Description
The plugin is affected by missing authorization. The
Ai1wmve Schedules Controller::save function for the 'admin post ai1wm schedule event save' endpoint does not verify user capabilities before saving schedule data. This allows authenticated attackers with subscriber-level access or higher to create scheduled export jobs and direct backup notifications to email addresses they control. Since these notifications contain the random backup filename, attackers can download full site backups, leading to the exposure of sensitive information.Recommendations
Update to a version later than 2.83.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
All-In-One Wp Migration Unlimited Extension