All-in-One WP Migration and Backup <= 7.97 - Authenticated (Administrator+) Stored Cross-Site Scripting via Import
All-in-One WP Migration and Backup
Minimum safe version
7.98
Update to 7.98 or later to address 20 fixable vulnerabilities
CVE-2024-10942
CVE-2024-9162
CVE-2024-8852
All-in-One WP Migration <= 2.0.2 - Authorization Bypass to Arbitrary File Upload
All-in-One WP Migration <= 2.0.4 - Missing Authorization to Database Export
All-in-One WP Migration <= 6.45 - Reflected Cross-Site Scripting
All-in-One WP Migration <= 6.97 - Authenticated Stored Cross-Site Scripting
All-in-One WP Migration <= 7.14 - Unauthenticated Backup Download
All-in-One WP Migration <= 7.62 - Authenticated (Admin+) Cross-Site Scripting
All-in-One WP Migration < 2.0.5 - Unauthenticated Database Export
All-in-One WP Migration < 6.46 - Reflected Cross-Site Scripting (XSS)
All-in-One WP Migration < 7.0 - Authenticated Cross-Site Scripting (XSS)
All-in-One WP Migration < 7.15 - Arbitrary Backup Download
CVE-2022-2546
WordPress Migration Plugin <= 2.0.4 - Unauthenticated Database Export
WordPress All-in-One WP Migration plugin <= 6.97 - Cross-Site Scripting (XSS) vulnerability (admin backend)
WordPress All-in-One WP Migration plugin <= 7.14 - Arbitrary Backup Download vulnerability
CVE-2022-1476
CVE-2021-24216