Record summary

CVE-2024-8852 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.86 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information such as full paths contained in the exposed log files.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 28, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 22, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListThrough 7.86affected

Default status: unaffected

CVE List, VulnCheckThrough 7.86affected

Nuclei templates

1
ProjectDiscoveryMEDIUMAll-in-One WP Migration < 7.87 - Unauthenticated Information DisclosureCVSS 5.3

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to unauthenticated information disclosure due to its error.log file being publicly accessible in versions before 7.87.

Impact

An unauthenticated attacker can access the error.log file, which may contain sensitive information such as full server path disclosures, backup filenames, and other debugging details. This information could be used in further attacks.

Remediation

Update the All-in-One WP Migration and Backup plugin to version 7.87 or later.

WeaknessesCWE-532
AuthorsFLX
Template tagscvecve2024wpscanwpwordpresswp-pluginall-in-one-wp-migrationdisclosurevkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
FOFA: body="/wp-content/plugins/all-in-one-wp-migration"

Source: ProjectDiscovery

References

4