๐Ÿ” CVE Alert

CVE-2026-12898

MEDIUM 6.5

All-in-One WP Migration and Backup < 7.106 - Unauthenticated Arbitrary-Location Log File Write via Path Traversal

CVSS Score
6.5
EPSS Score
0.2%
EPSS Percentile
6th

The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file path, allowing unauthenticated attackers to create or append a log file in arbitrary locations outside its intended storage directory.

Vendor unknown
Product all-in-one wp migration and backup
Published Jul 20, 2026
Last Updated Jul 20, 2026
Stay Ahead of the Next One

Get instant alerts for unknown all-in-one wp migration and backup

Be the first to know when new medium vulnerabilities affecting unknown all-in-one wp migration and backup are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / All-in-One WP Migration and Backup
7.87 < 7.106

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/c90553e4-8e1a-4c99-a28f-a0de8d635caa/

Credits

Jakub Herman WPScan