CVE-2022-1476

MEDIUM

All-in-One WP Migration < 7.58 - Authenticated Arbitrary File Deletion via Directory Traversal

Title source: llm
STIX 2.1

Description

The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to insufficient file validation via the ~/lib/model/class-ai1wm-backups.php file, in versions up to, and including, 7.58. This can be exploited by administrative users, and users who have access to the site's secret key.

Scores

CVSS v3 6.6
EPSS 0.4749
EPSS Percentile 98.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-22
Status published
Products (2)
servmask/All-in-One WP Migration and Backup < 7.58
servmask/all-in-one_wp_migration < 7.58
Published May 10, 2022
Tracked Since Feb 18, 2026