The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to insufficient file validation via the ~/lib/model/class-ai1wm-backups.php file, in versions up to, and including, 7.58. This can be exploited by administrative users, and users who have access to the site's secret key.
References
Configurations
History
11 Jan 2024, 09:15
Type | Values Removed | Values Added |
---|---|---|
CWE | ||
References |
|
Information
Published : 2022-05-10 20:15
Updated : 2024-02-28 19:09
NVD link : CVE-2022-1476
Mitre link : CVE-2022-1476
CVE.ORG link : CVE-2022-1476
JSON object : View
Products Affected
servmask
- all-in-one_wp_migration
CWE
No CWE.