All-in-One WP Migration Unlimited Extension Missing Authorization Vulnerability Allowing Arbitrary Backup Schedule Creation and Download

Vulnerability

A missing authorization vulnerability has been identified in the All-in-One WP Migration Unlimited Extension for WordPress, affecting versions through 2.83. The issue arises because the 'Ai1wmve_Schedules_Controller::save' handler for 'admin_post_ai1wm_schedule_event_save' fails to verify user capabilities before saving schedule data. This vulnerability enables authenticated attackers with subscriber-level access and above to create scheduled export jobs and send backup notifications to email addresses controlled by the attacker. These notifications include the random backup filename, allowing full site backups to be downloaded from the target site, which could result in the exposure of sensitive information.

Impact

Exploitation of this vulnerability allows for unauthorized creation of backup schedules and downloading of backup files, potentially leading to exposure of sensitive information from the affected WordPress site.

Remediation

Users are advised to update the All-in-One WP Migration Unlimited Extension to version 2.84 or a newer patched version.

Added: May 6, 2026, 4:19 AM
Updated: May 6, 2026, 4:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.8
remediation
0.0
relevance
7.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.