Impact
The All‑in‑One WP Migration Unlimited Extension fails to sanitize or escape the ai1wm_backups_path parameter, allowing an attacker with Subscriber level or higher to inject arbitrary JavaScript that is stored and later executed whenever an administrator opens the plugin settings page. This stored XSS can lead to cookie theft, session hijacking, or further compromise of the WordPress site.
Affected Systems
All versions of Servmask’s All‑in‑One WP Migration Unlimited Extension up to and including 2.84 are impacted. WordPress sites that use this plugin and host subscriber accounts are affected. Version 2.84 contains only a partial patch and newer releases are required for full remediation.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with at least Subscriber access. Attackers supply malicious payload via the ai1wm_backups_path field and wait for an administrator to view the settings page, at which point the script runs. While the vector is authenticated and the privilege escalation is limited, the risk is sufficient to warrant prompt action.
OpenCVE Enrichment