A SQL Injection vulnerability has been reported in All-in-One WP Migration and Backup plugin for WordPress, which could allow an unauthenticated remote attacker to inject malicious SQL statements, access sensitive database information, obtain the plugin¿s secret key, and potentially execute arbitrary code on affected WordPress installations.
Target Audience:
All organizations and administrators using affected versions of the All-in-One WP Migration and Backup plugin for WordPress.
Risk Assessment:
High risk of sensitive data exposure and compromise of affected WordPress installations.
Impact Assessment:
Potential for malicious SQL execution, disclosure of sensitive database information, compromise of the plugin¿s secret key, arbitrary code execution, and complete compromise of affected WordPress installations.
The information provided herein is on "as is" basis, without warranty of any kind.