Description
WordPress Plugin All-in-One WP Migration is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently export a copy of the database, plugins, themes, and uploaded files. WordPress Plugin All-in-One WP Migration version 2.0.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.0.5 or latest
References
Related Vulnerabilities
Ruby CVE-2019-15845 Vulnerability (CVE-2019-15845)
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall Cross-Site Request Forgery (5.1.0)
Internet Information Services Other Vulnerability (CVE-2000-0413)
Drupal Improper Input Validation Vulnerability (CVE-2019-6339)
WordPress Plugin WP Maintenance Mode Multiple Vulnerabilities (2.0.3)