CVE-2022-2546
The All-in-One WP Migration plugin versions before 7.63 contains an improper content type specification and fails to adequately sanitize output from the ai1wm_export AJAX handler, enabling an attacker to inject malicious HTML or JavaScript code into responses that execute within a user's browser session. Exploitation of this vulnerability requires familiarity with a hardcoded static secret key that must be known to craft the malicious request. Any site visitor who unknowingly submits such a crafted request becomes vulnerable to having arbitrary code executed in their authenticated context.
Based on public CVE data (MITRE/NVD).