Description
WordPress Plugin All-in-One WP Migration is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently export a copy of the database, plugins, themes, and uploaded files. WordPress Plugin All-in-One WP Migration version 2.0.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.0.5 or latest
References
Related Vulnerabilities
Oracle HTTP Server Uncontrolled Recursion Vulnerability (CVE-2021-42717)
osCommerce Other Vulnerability (CVE-2003-1219)
WordPress Plugin Anti-Malware Security and Brute-Force Firewall Cross-Site Scripting (4.15.22)
PostgreSQL 7PK - Security Features Vulnerability (CVE-2016-2193)
WordPress Plugin Featured Comments Cross-Site Request Forgery (1.2.4)