Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress All-in-One WP Migration and Backup — verificado contra la base de datos de seguridad local de WP Clinic.
Qué hace este plugin
- Slug:
all-in-one-wp-migration
- 5000000+ instalaciones activas
backupcloneexport-importmigratemove wordpress
Estado de mantenimiento
- Última versión conocida: 7.106
- Requiere PHP: 5.3+
- PHP máximo soportado (analizado): <8.0
Vulnerabilidades conocidas
7 CVEs conocidos registrados para All-in-One WP Migration and Backup.
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2024-10942
|
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.90 |
Deserialización de datos no confiables |
Alta
7,5
|
< 7.90
|
7.90 |
2025-03-12 |
✓ corregido en la última versión
|
|
CVE-2024-9162
|
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.87 |
Control incorrecto de la generación de código (inyección de código) |
Alta
7,2
|
< 7.87
|
7.87 |
2024-10-27 |
✓ corregido en la última versión
|
|
CVE-2024-8852
|
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.87 |
Exposición de información sensible a un actor no autorizado |
Media
5,3
|
< 7.87
|
7.87 |
2024-10-21 |
✓ corregido en la última versión
|
|
CVE-2022-2546
|
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.63 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
4,7
|
< 7.63
|
7.63 |
2022-08-23 |
✓ corregido en la última versión
|
|
—
|
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.63 |
— |
Desconocido
|
< 7.63
|
7.63 |
2022-08-15 |
✓ corregido en la última versión
|
|
CVE-2022-1476
|
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.59 |
Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) |
Media
6,5
|
< 7.59
|
7.59 |
2022-04-28 |
✓ corregido en la última versión
|
|
CVE-2021-24216
|
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.41 |
Carga de archivos sin restricción de tipo peligroso |
Alta
7,2
|
< 7.41
|
7.41 |
2022-02-07 |
✓ corregido en la última versión
|
|
—
|
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.15 |
— |
Desconocido
|
< 7.15
|
7.15 |
2020-03-25 |
✓ corregido en la última versión
|
CVE-2024-10942
The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.89 via deserialization of untrusted input in the 'replace_serialized_values' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code. An administrator must export and restore a backup in order to trigger the exploit.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-9162
The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to arbitrary PHP Code Injection due to missing file type validation during the export in all versions up to, and including, 7.86. This makes it possible for authenticated attackers, with Administrator-level access and above, to create an export file with the .php extension on the affected site's server, adding an arbitrary PHP code to it, which may make remote code execution possible.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-8852
The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.86 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information such as full paths contained in the exposed log files.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2022-2546
The All-in-One WP Migration WordPress plugin before 7.63 uses the wrong content type, and does not properly escape the response from the ai1wm_export AJAX action, allowing an attacker to craft a request that when submitted by any visitor will inject arbitrary html or javascript into the response that will be executed in the victims session. Note: This requires knowledge of a static secret key
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.63
The All-in-One WP Migration plugin for WordPress is vulnerable to cross-site scripting via the 'storage' parameter in versions up to, and including, 7.62 due to insufficient input sanitization and output escaping. This allows attackers to execute arbitrary web scripts in victim's browsers. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2022-1476
The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to insufficient file validation via the ~/lib/model/class-ai1wm-backups.php file, in versions up to, and including, 7.58. This can be exploited by administrative users, and users who have access to the site's secret key.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2021-24216
The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on file upload in versions up to, and including, 7.40. This makes it possible for authenticated attackers with administrative privileges to upload arbitrary files on the affected sites server which may make remote code execution possible.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.15
Arbitrary Backup Download vulnerability found by Kamil Vavra in WordPress All-in-One WP Migration plugin (versions <= 7.14).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
+ 12 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
—
|
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.15 |
— |
Desconocido
|
< 7.15
|
7.15 |
2020-01-20 |
✓ corregido en la última versión
|
|
—
|
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.0 |
— |
Desconocido
|
< 7.0
|
7.0 |
2019-07-18 |
✓ corregido en la última versión
|
|
—
|
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.0 |
— |
Desconocido
|
< 7.0
|
7.0 |
2019-07-18 |
✓ corregido en la última versión
|
|
—
|
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 6.46 |
— |
Desconocido
|
< 6.46
|
6.46 |
2017-06-20 |
✓ corregido en la última versión
|
|
—
|
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 2.0.5 |
— |
Desconocido
|
< 2.0.5
|
2.0.5 |
2015-03-19 |
✓ corregido en la última versión
|
|
—
|
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 2.0.5 |
— |
Desconocido
|
< 2.0.5
|
2.0.5 |
2015-03-19 |
✓ corregido en la última versión
|
|
—
|
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 2.0.3 |
— |
Desconocido
|
< 2.0.3
|
2.0.3 |
2014-11-05 |
✓ corregido en la última versión
|
|
CVE-2025-8490
|
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.98 |
— |
Media
4,4
|
< 7.98
|
7.98 |
0000-00-00 |
✓ corregido en la última versión
|
|
—
|
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.15 |
— |
Desconocido
|
< 7.15
|
7.15 |
— |
✓ corregido en la última versión
|
|
—
|
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.0 |
— |
Desconocido
|
< 7.0
|
7.0 |
— |
✓ corregido en la última versión
|
|
—
|
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 6.46 |
— |
Desconocido
|
< 6.46
|
6.46 |
— |
✓ corregido en la última versión
|
|
—
|
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 2.0.5 |
— |
Desconocido
|
< 2.0.5
|
2.0.5 |
— |
✓ corregido en la última versión
|
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.15
The All-in-One WP Migration plugin for WordPress is vulnerable to unauthenticated arbitrary back-up downloads due to insufficient filename randomization that made it possible for unauthenticated attackers to brute force back-up filenames in unique situations in versions up to, and including, 7.14. This would make it possible for unauthenticated attackers to discover information from files contained in the back-ups that could be used to aid further attacks or lead to simply sensitive information disclosure.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.0
Cross-Site Scripting (XSS) vulnerability (admin backend) found by Connum in WordPress All-in-One WP Migration plugin (versions <= 6.97).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.0
The All-in-One WP Migration plugin for WordPress is vulnerable to Cross-Site Scripting due to the fact that the backup description on the backup history overview page does not sanitize/escape html entities when generating the input field.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 6.46
The All-in-One WP Migration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘secret_key’ parameter in versions up to, and including, 6.45 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 2.0.5
Because of this vulnerability, users, which have access to the database, can get uploads, themes, plugins of your website.
Update the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 2.0.5
The All-in-One WP Migration plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'router()' function in versions up to, and including, 2.0.4. This makes it possible for unauthenticated attackers to export a complete copy of the vulnerable service's database.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 2.0.3
The All-in-One WP Migration plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the import() function in versions up to, and including, 2.0.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to upload arbitrary files.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-8490
The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Import in all versions up to, and including, 7.97 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.15
Lack of randomness in the backup filenames could allow unauthenticated attackers to guess and download them
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.0
An attacker would already have to be able to either compromise the database or gain access to a user account with high enough privileges to view the backup history, so some damage has already been done, but such an attacker could then also insert some XSS in order to compromise other admin users.
When double-clicking the backup description on the backup history overview page, in order to edit the description text, the text is not sanitized/escaped via html entities when generating the input field.
This has been reported to the plugin author on 2 July 2019 and confirmed to be fixed in version 7.0 on 17 July 2019.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 6.46
All-in-One WP Migration is vulnerable to Reflected Cross-Site Scripting on secret_key parameter.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 2.0.5
Unauthenticated users can export a complete copy of the WordPress database, all plugins, themes, and uploaded files.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Cómo solucionarlo
Mantén All-in-One WP Migration and Backup actualizado — 7.106 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.
Alternativas más seguras / más establecidas