Description
The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Insufficient Credential Protection in versions up to, and including, 7.110. This is due to the `Ai1wm_Main_Controller::init()` method — registered on the `admin_init` hook, which fires unauthenticated on `admin-ajax.php` and `admin-post.php` requests — reading `$_SERVER['PHP_AUTH_USER']` and `$_SERVER['PHP_AUTH_PW']` from any incoming request and writing them to the `ai1wm_auth_header` option via `update_option()` as a reversible base64-encoded string, with no capability check, nonce verification, `is_user_logged_in()` check, or confirmation that Basic authentication actually succeeded. This makes it possible for unauthenticated attackers to capture into the database, in reversible base64 form, any WordPress Application Password or HTTP Basic credential presented to `/wp-admin/` by a legitimate integration, or to overwrite the stored credential with an attacker-chosen value by sending an anonymous request carrying a crafted `Authorization: Basic` header. This is particularly impactful in environments using WordPress Application Passwords for REST API or third-party integrations, as those credentials are transmitted as HTTP Basic auth to `/wp-admin/` and will be silently harvested via this unauthenticated write path.
Published: 2026-09-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Credential Theft
Action: Patch Now
AI Analysis

Impact

The vulnerability resides in the init method of the All‑in‑One WP Migration and Backup plugin, which executes on WordPress admin initializations without performing any authentication checks. An unauthenticated request that includes an Authorization header is parsed, and the supplied username and password are stored in the WordPress options table as a reversible base64 string. This allows an attacker to harvest or overwrite credentials that a legitimate user sends to /wp-admin/, such as WordPress Application Passwords used by the REST API or external integrations. The captured credentials can be redeemed to gain authenticated access to the site or its APIs.

Affected Systems

The vulnerability affects the servmask All‑in‑One WP Migration and Backup plugin for WordPress versions up to and including 7.110. Any WordPress installation that has this plugin installed and active, regardless of whether it is used for backup or migration, is susceptible to credential theft whenever the site is exposed to the public internet or to employees.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, reflecting that the vulnerability requires the attacker to be able to send crafted requests to the WordPress admin endpoint but does not offer direct arbitrary code execution. The EPSS score of <1% suggests that, in the current data set, there is low exploitation activity observed. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation at this time. Nevertheless, because the flaw reveals user credentials with no authentication check, the potential impact on confidentiality and compromise of dependent services can be significant in environments that use application passwords for API access.

Generated by OpenCVE AI on September 18, 2026 at 02:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the All‑in‑One WP Migration and Backup plugin to version 7.111 or later to eliminate the unauthenticated credential capture path.
  • If an immediate update is unavailable, disable or uninstall the plugin to prevent unauthorized writes to the options table.
  • Audit the ai1wm_auth_header option and revoke any WordPress Application Passwords or API keys that may have been exposed by the vulnerability.

Generated by OpenCVE AI on September 18, 2026 at 02:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Insufficient Credential Protection in versions up to, and including, 7.110. This is due to the `Ai1wm_Main_Controller::init()` method — registered on the `admin_init` hook, which fires unauthenticated on `admin-ajax.php` and `admin-post.php` requests — reading `$_SERVER['PHP_AUTH_USER']` and `$_SERVER['PHP_AUTH_PW']` from any incoming request and writing them to the `ai1wm_auth_header` option via `update_option()` as a reversible base64-encoded string, with no capability check, nonce verification, `is_user_logged_in()` check, or confirmation that Basic authentication actually succeeded. This makes it possible for unauthenticated attackers to capture into the database, in reversible base64 form, any WordPress Application Password or HTTP Basic credential presented to `/wp-admin/` by a legitimate integration, or to overwrite the stored credential with an attacker-chosen value by sending an anonymous request carrying a crafted `Authorization: Basic` header. This is particularly impactful in environments using WordPress Application Passwords for REST API or third-party integrations, as those credentials are transmitted as HTTP Basic auth to `/wp-admin/` and will be silently harvested via this unauthenticated write path.
Title All-in-One WP Migration and Backup <= 7.110 - Unauthenticated Insufficient Credential Protection via Authorization Basic Header
Weaknesses CWE-522
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-18T14:45:13.520Z

Reserved: 2026-09-10T18:41:07.024Z

Link: CVE-2026-89064

cve-icon Vulnrichment

Updated: 2026-09-18T14:39:44.675Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T03:16:32.500

Modified: 2026-09-18T15:17:17.637

Link: CVE-2026-89064

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T02:30:06Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials