What the vulnerability does
01Description
Missing Authorization vulnerability in ServMask All-in-One WP Migration Box Extension, ServMask All-in-One WP Migration OneDrive Extension, ServMask All-in-One WP Migration Dropbox Extension, ServMask All-in-One WP Migration Google Drive Extension.This issue affects All-in-One WP Migration Box Extension: from n/a through 1.53; All-in-One WP Migration OneDrive Extension: from n/a through 1.66; All-in-One WP Migration Dropbox Extension: from n/a through 3.75; All-in-One WP Migration Google Drive Extension: from n/a through 2.79.
Explanation of Vulnerability in Simple Terms
02Summary
The All-in-One WP Migration Box Extension through version 1.53 lacks proper authorization checks, allowing unauthenticated attackers to read, modify, or delete site data without logging in. An attacker can exploit this over the network without user interaction. This affects backup and migration functionality, potentially exposing sensitive site information and configurations.
What an attacker can do
03Attacker Capabilities
Read, modify, or delete site backups and migration data without authentication.
Potential impact on your site
04Site Impact
Attackers can access, alter, or destroy site backups and migration files without logging in.
Conditions required to exploit
05Prerequisites
Network access to the WordPress site; no authentication or user interaction required.
Key dates
06Disclosure timeline
June 19, 2024
CVE published
April 28, 2026
Record updated