CVE-2022-1476
Last modified
CVE-2022-1476 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to insufficient file validation via the ~/lib/model/class-ai1wm-backups.php file, in versions up to, and including, 7.58. This can be exploited by administrative users, and users who have access to the site's secret key.. EPSS estimates a 47.49% chance of exploitation in the next 30 days.
Description
The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to insufficient file validation via the ~/lib/model/class-ai1wm-backups.php file, in versions up to, and including, 7.58. This can be exploited by administrative users, and users who have access to the site's secret key.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Servmask | All-In-One Wp Migration | <= 7.58 |
References
- https://www.wordfence.com/vulnerability-advisories/#CVE-2022-1476Third Party Advisory
- https://www.wordfence.com/vulnerability-advisories/#CVE-2022-1476Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-1476?
How severe is CVE-2022-1476?
How do I fix CVE-2022-1476?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-1470The Ultimate WooCommerce CSV Importer WordPress plugin throu…6.1
- CVE-2022-1471SnakeYaml's Constructor() class does not restrict types whic…9.8
- CVE-2022-1472The Better Find and Replace WordPress plugin before 1.3.6 do…7.2
- CVE-2022-1473The OPENSSL_LH_flush() function, which empties a hash table,…7.5
- CVE-2022-1474The WP Event Manager WordPress plugin before 3.1.28 does not…6.1
- CVE-2022-1475An integer overflow vulnerability was found in FFmpeg versio…5.5
- CVE-2022-1477Use after free in Vulkan in Google Chrome prior to 101.0.495…8.8
- CVE-2022-1478Use after free in SwiftShader in Google Chrome prior to 101.…8.8
- CVE-2022-1479Use after free in ANGLE in Google Chrome prior to 101.0.4951…8.8
- CVE-2022-1480Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-1481Use after free in Sharing in Google Chrome on Mac prior to 1…8.8
- CVE-2022-1482Inappropriate implementation in WebGL in Google Chrome prior…6.5
Are you affected by CVE-2022-1476?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
