Impact
The All-in-One WP Migration and Backup plugin before version 7.111 fails to enforce capability checks on several AJAX actions and depends only on a secret that is disclosed to users who can export the site. A user with export permission but not import permission can import an arbitrary archive, which grants them administrator access. This flaw lets a non-admin role with export rights elevate privileges and access the WordPress admin panel.
Affected Systems
WordPress sites using All-in-One WP Migration and Backup at any version older than 7.111 and that enable the export function for roles that lack the All-in-One WP Migration and Backup WordPress plugin before 7.111's own import capability are vulnerable. Because the default configuration does not assign export rights to a role that does not also have import rights, the issue appears only when administrators apply custom role permissions.
Risk and Exploitability
The CVSS score of 7.2 reflects high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a user to possess export capability without import capability, a situation that can arise with custom role setups. Once those conditions are met, the attack is trivial due to the missing internal capability check, enabling an attacker to elevate privileges.
OpenCVE Enrichment