All 5 CVE vulnerabilities found in All-in-One WP Migration and Backup, with AI-generated Chinese analysis, references, and POCs.
Vendor: servmask
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-8490 | All-in-One WP Migration and Backup <= 7.97 - Authenticated (Administrator+) Stored Cross-Site Scripting via Import CWE-79 | 4.4 | Medium | 2025-08-26 |
| CVE-2024-10942 | All in One WP Migration <= 7.89 - Unauthenticated PHP Object Injection CWE-502 | 7.5 | High | 2025-03-13 |
| CVE-2024-9162 | All-in-One WP Migration and Backup <= 7.86 - Authenticated (Administrator+) Arbitrary PHP Code Injection CWE-94 | 7.2 | High | 2024-10-28 |
| CVE-2024-8852 | All-in-One WP Migration and Backup <= 7.86 - Unauthenticated Information Disclosure via Error Logs CWE-200 | 5.3 | Medium | 2024-10-22 |
| CVE-2022-1476 | All-in-One WP Migration <= 7.58 - Directory Traversal to File Deletion on Windows Hosts CWE-22 | 6.6 | Medium | 2022-05-10 |
All 5 known CVE vulnerabilities affecting All-in-One WP Migration and Backup with full Chinese analysis, references, and POCs where available.