WordPress All-in-One WP Migration and Backup是WordPress基金会的一款全方位网站迁移与备份组件。 WordPress All-in-One WP Migration and Backup 7.106之前版本存在路径遍历漏洞,该漏洞源于未正确清理用户提供的值就用于构建文件路径,可能导致未经身份验证的攻击者在预期存储目录之外的任意位置创建或追加日志文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | All-in-One WP Migration and Backup | 7.87< 7.106 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | All-in-One WP Migration and Backup | 7.87 ~ 7.106 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file path. This makes it possible for unauthenticated attackers to create or append a log file in arbitrary locations outside the intended storage directory. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-12898.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2026-12972 | PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Payment Metadata Tampering | |
| CVE-2026-8825 | Elementor < 4.1.4 - Contributor+ Sensitive Information Disclosure via REST API | |
| CVE-2026-13156 | MailerSend - Official SMTP Integration < 1.0.8 - Settings Deletion and Plugin Deactivation | |
| CVE-2026-13147 | Kirki < 6.0.12 - Unauthenticated Server-Side Request Forgery via kirki_get_apis | |
| CVE-2026-13142 | Passwordless Login by VentraConnect < 1.4.1 - Unauthenticated Account Takeover via Email O | |
| CVE-2026-13432 | ThumbPress < 6.2.2 - Subscriber+ Plugin Deactivation | |
| CVE-2026-9833 | Tag Groups < 2.2.0 - Reflected XSS via 'tag_groups_task' Parameter | |
| CVE-2026-12970 | LearnPress < 4.4.1 - Reflected XSS via c_search | |
| CVE-2026-12973 | PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Key Disclosure and Order Status Mo | |
| CVE-2026-11349 | Modern Events Calendar (Lite & Pro) < 7.34.0 - Unauthenticated SQL Injection via mec_list_ | |
| CVE-2026-12724 | Kirki < 6.0.12 - Unauthenticated HTML Injection in Password Reset Email via kirki-forgot-p | |
| CVE-2026-12723 | Kirki < 6.0.12 - Unauthenticated Arbitrary Comment Modification and Moderation Bypass via | |
| CVE-2026-12592 | SlimStat Analytics < 5.5.0 - Unauthenticated Stored XSS via CF-IPCountry Header | |
| CVE-2026-11868 | WP Travel < 11.7.1 - Unauthenticated Arbitrary Booking Cancellation | |
| CVE-2026-10081 | Unlimited Elements for Elementor < 2.0.11 - Unauthenticated Stored XSS via Google Reviews | |
| CVE-2026-10724 | Reviews Feed < 2.6.5 - Unauthenticated Stored Arbitrary Shortcode Execution via Google Rev | |
| CVE-2026-10755 | All in One SEO < 4.9.9 – Contributor+ Incorrect Authorization via AI Integration |
No comments yet