The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file path, allowing unauthenticated attackers to create or append a log file in arbitrary locations outside its intended storage directory.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-20 07:16
Updated : 2026-07-20 20:39
NVD link : CVE-2026-12898
Mitre link : CVE-2026-12898
CVE.ORG link : CVE-2026-12898
JSON object : View
Products Affected
No product.
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
