The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.83. This is due to the 'Ai1wmve_Schedules_Controller::save' handler for 'admin_post_ai1wm_schedule_event_save' not verifying user capabilities before saving schedule data. This makes it possible for authenticated attackers, with subscriber-level access and above, to create scheduled export jobs and send backup notifications to attacker-controlled email addresses. Because such notifications include the random backup filename, full site backups can subsequently be downloaded from the target site, resulting in sensitive information exposure.
References
Configurations
No configuration.
History
06 May 2026, 04:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-06 04:16
Updated : 2026-06-17 10:59
NVD link : CVE-2026-5753
Mitre link : CVE-2026-5753
CVE.ORG link : CVE-2026-5753
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
