Back to Advisories
πŸ”” CVE Advisory

CVE-2022-1476

All-in-one WP Migration

The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to insufficient file validation via the ~/lib/model/class-ai1wm-backups.php file, in versions up to, and including, 7.58. This can be exploited by administrative users, and users who have access to the site’s secret key on WordPress instances with Windows hosts.

Year 2022
Published July 22, 2022

Advisory Information

Affected Product All-in-one WP Migration
Title CVE-2022-1476
Description

The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to insufficient file validation via the ~/lib/model/class-ai1wm-backups.php file, in versions up to, and including, 7.58. This can be exploited by administrative users, and users who have access to the site’s secret key on WordPress instances with Windows hosts.

Year 2022
Published Date July 22, 2022

Affected Vendors