CVE-2024-9162

HIGH

All-in-One WP Migration & Backup <7.86 - Code Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-9162. PoCs published by d0n601.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2024-9162, an authenticated arbitrary file upload vulnerability in the All-in-One WP Migration and Backup WordPress plugin. The exploit leverages missing file type validation to upload a malicious PHP file, achieving remote code execution.

Description

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to arbitrary PHP Code Injection due to missing file type validation during the export in all versions up to, and including, 7.86. This makes it possible for authenticated attackers, with Administrator-level access and above, to create an export file with the .php extension on the affected site's server, adding an arbitrary PHP code to it, which may make remote code execution possible.

Exploits (1)

nomisec WORKING POC 7 stars
by d0n601 · poc
https://github.com/d0n601/CVE-2024-9162

This repository contains a functional exploit for CVE-2024-9162, an authenticated arbitrary file upload vulnerability in the All-in-One WP Migration and Backup WordPress plugin. The exploit leverages missing file type validation to upload a malicious PHP file, achieving remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: All-in-One WP Migration and Backup <= 7.86
Auth required
Prerequisites: Administrator-level access to the WordPress site · Valid ai1wm_secret_key · Network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 7.2
EPSS 0.0267
EPSS Percentile 83.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (2)
servmask/All-in-One WP Migration and Backup < 7.86
yaniiliev/All-in-One WP Migration and Backup < 7.86
Published Oct 28, 2024
Tracked Since Feb 18, 2026