CVE-2023-40004 HIGH

CVE-2023-40004: Unauth. Access Token Manipulation vulnerability in multiple ServMask WordPress plugins

Vendor Servmask
Product All-in-One WP Migration Box Extension
Weakness CWE-862 · Missing authorization
Published June 19, 2024
Last update April 28, 2026

CVSS base score

7.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

Missing Authorization vulnerability in ServMask All-in-One WP Migration Box Extension, ServMask All-in-One WP Migration OneDrive Extension, ServMask All-in-One WP Migration Dropbox Extension, ServMask All-in-One WP Migration Google Drive Extension.This issue affects All-in-One WP Migration Box Extension: from n/a through 1.53; All-in-One WP Migration OneDrive Extension: from n/a through 1.66; All-in-One WP Migration Dropbox Extension: from n/a through 3.75; All-in-One WP Migration Google Drive Extension: from n/a through 2.79.

Explanation of Vulnerability in Simple Terms

02Summary

The All-in-One WP Migration Box Extension through version 1.53 lacks proper authorization checks, allowing unauthenticated attackers to read, modify, or delete site data without logging in. An attacker can exploit this over the network without user interaction. This affects backup and migration functionality, potentially exposing sensitive site information and configurations.

What an attacker can do

03Attacker Capabilities

Read, modify, or delete site backups and migration data without authentication.

Potential impact on your site

04Site Impact

Attackers can access, alter, or destroy site backups and migration files without logging in.

Conditions required to exploit

05Prerequisites

Network access to the WordPress site; no authentication or user interaction required.

Key dates

06Disclosure timeline

June 19, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE