All-in-One WP Migration Vulnerabilities

All-in-One WP Migration < 7.59 – Admin+ File Deletion on Windows Hosts via Path Traversal

Description

The plugin is vulnerable to arbitrary file deletion via directory traversal due to insufficient file validation via the ~/lib/model/class-ai1wm-backups.php file which can be exploited by administrative users, and users who have access to the site’s secret key on WordPress instances with Windows hosts.

Affects Plugins

all-in-one-wp-migration

Fixed in version 7.59

References

CVE

CVE-2022-1476

URL

Classification

Type

TRAVERSAL

OWASP top 10

A1: Injection

CWE

CWE-22

Miscellaneous

Original Researcher

haidv35 (Viettel Cyber Security)

Verified

Yes

WPVDB ID

6e233311-d8ea-4ed4-8959-6c88f786ceef

Timeline

Publicly Published

2022-04-28 (about 2 days ago)

Added

2022-04-28 (about 2 days ago)

Last Updated

2022-04-29 (about 1 days ago)

Related Post

Leave a Reply

Your email address will not be published. Required fields are marked *