cleantalk
Vulnerabilities and Security Researches

All-in-One WP Migration, b3716979a3fcf975789fc7eaaf635e9269b3855c

Published on
Jul 18, 2019
Research Description
All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.0 All-in-One WP Migration <= 6.97 - Authenticated Stored Cross-Site Scripting The All-in-One WP Migration plugin for WordPress is vulnerable to Cross-Site Scripting due to the fact that the backup description on the backup history overview page does not sanitize/escape html entities when generating the input field.
Affected versions
max 7.0.
Status
vulnerable