CVE · Medium

CVE-2024-8852 — All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.87

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-8852 All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.87 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 7.87 7.87 2024-10-21

CVE-2024-8852

The All-in-One WP Migration and Backup plugin contains a security flaw that allows unauthorized access to sensitive data stored in its log files, which are inadvertently made public. Versions of this plugin up to 7.86 include this vulnerability, putting users at risk of having their full file paths exposed. This issue stems from the plugin's handling of log files, allowing attackers to view potentially sensitive information without needing authentication.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.