All-in-One WP Migration <= 7.14 - Unauthenticated Backup Download
Strategic Overview
< 7.15N/AVulnerability Overview
The All-in-One WP Migration plugin for WordPress is vulnerable to unauthenticated arbitrary back-up downloads due to insufficient filename randomization that made it possible for unauthenticated attackers to brute force back-up filenames in unique situations in versions up to, and including, 7.14. This would make it possible for unauthenticated attackers to discover information from files contained in the back-ups that could be used to aid further attacks or lead to simply sensitive information disclosure.
Technical Analysis
REMEDIATION: Update to version 7.15, or a newer patched version --- IDENTIFIER: CWE-330 (Use of Insufficiently Random Values) The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C