CVE-2024-9162

HIGH

All-in-One WP Migration & Backup <7.86 - Code Injection

Title source: llm
STIX 2.1

Description

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to arbitrary PHP Code Injection due to missing file type validation during the export in all versions up to, and including, 7.86. This makes it possible for authenticated attackers, with Administrator-level access and above, to create an export file with the .php extension on the affected site's server, adding an arbitrary PHP code to it, which may make remote code execution possible.

Exploits (1)

nomisec WORKING POC 7 stars
by d0n601 · poc
https://github.com/d0n601/CVE-2024-9162

Scores

CVSS v3 7.2
EPSS 0.6261
EPSS Percentile 98.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (2)
servmask/All-in-One WP Migration and Backup < 7.86
yaniiliev/All-in-One WP Migration and Backup < 7.86
Published Oct 28, 2024
Tracked Since Feb 18, 2026