All-in-One WP Migration and Backup < 7.108 - Multisite Subsite Admin+ Network-Wide PHP Code Execution via REST Import
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 7.2epss 0.3%
exploitation probability
0.3%top 75% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import functionality to network administrators on multisite installations, allowing an administrator of a single subsite to execute arbitrary PHP code across the entire network.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
Unknown · All-in-One WP Migration and Backuppublic PoCs found — 1
cve_referencewpscan.com/vulnerability/13b57cdc-d954-4db6-94c2-53ad04ab0d34/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.