Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 06 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 06 May 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Servmask
Servmask all-in-one Wp Migration Unlimited Extension Wordpress Wordpress wordpress |
|
| Vendors & Products |
Servmask
Servmask all-in-one Wp Migration Unlimited Extension Wordpress Wordpress wordpress |
Wed, 06 May 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.83. This is due to the 'Ai1wmve_Schedules_Controller::save' handler for 'admin_post_ai1wm_schedule_event_save' not verifying user capabilities before saving schedule data. This makes it possible for authenticated attackers, with subscriber-level access and above, to create scheduled export jobs and send backup notifications to attacker-controlled email addresses. Because such notifications include the random backup filename, full site backups can subsequently be downloaded from the target site, resulting in sensitive information exposure. | |
| Title | All-in-One WP Migration Unlimited Extension <= 2.83 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Backup Schedule Creation and Backup File Download | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-05-06T12:57:42.449Z
Reserved: 2026-04-07T16:14:53.795Z
Link: CVE-2026-5753
Updated: 2026-05-06T12:57:36.834Z
Status : Deferred
Published: 2026-05-06T04:16:09.097
Modified: 2026-05-06T13:06:42.220
Link: CVE-2026-5753
No data.
OpenCVE Enrichment
Updated: 2026-05-06T09:21:18Z