Description
WordPress Plugin All-in-One WP Migration is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin All-in-One WP Migration version 7.0 is vulnerable.
Remediation
Update to plugin version 7.1 or latest
References
Related Vulnerabilities
WordPress Plugin Simple:Press 'sf-header-forum.php' SQL Injection (4.3.0)
Contao Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2025-57757)
Craft CMS Server-Side Request Forgery (SSRF) Vulnerability (CVE-2026-25492)
MySQL CVE-2022-39403 Vulnerability (CVE-2022-39403)
WordPress Plugin Comments-wpDiscuz Cross-Site Request Forgery (3.2.8)