Impact
The vulnerability resides in the init method of the All‑in‑One WP Migration and Backup plugin, which executes on WordPress admin initializations without performing any authentication checks. An unauthenticated request that includes an Authorization header is parsed, and the supplied username and password are stored in the WordPress options table as a reversible base64 string. This allows an attacker to harvest or overwrite credentials that a legitimate user sends to /wp-admin/, such as WordPress Application Passwords used by the REST API or external integrations. The captured credentials can be redeemed to gain authenticated access to the site or its APIs.
Affected Systems
The vulnerability affects the servmask All‑in‑One WP Migration and Backup plugin for WordPress versions up to and including 7.110. Any WordPress installation that has this plugin installed and active, regardless of whether it is used for backup or migration, is susceptible to credential theft whenever the site is exposed to the public internet or to employees.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, reflecting that the vulnerability requires the attacker to be able to send crafted requests to the WordPress admin endpoint but does not offer direct arbitrary code execution. The EPSS score of <1% suggests that, in the current data set, there is low exploitation activity observed. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation at this time. Nevertheless, because the flaw reveals user credentials with no authentication check, the potential impact on confidentiality and compromise of dependent services can be significant in environments that use application passwords for API access.
OpenCVE Enrichment