← Back to browse · API

CVE-2022-1476

Severity
MEDIUM
CVSS
6.6
EPSS
0.47077
Risk score
42.88
CISA KEV
No
PoC
No
Published
2022-05-10
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2022-24777, GHSA-QJJ4-MXPM-P3M8
Products
ServMask:All-in-One WP Migration and Backup 0 ≤7.58
Sources
euvd EUVD-2022-24777

Description

The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to insufficient file validation via the ~/lib/model/class-ai1wm-backups.php file, in versions up to, and including, 7.58. This can be exploited by administrative users, and users who have access to the site's secret key.

References