Description
WordPress Plugin All-in-One WP Migration is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently export a copy of the database, plugins, themes, and uploaded files. WordPress Plugin All-in-One WP Migration version 2.0.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.0.5 or latest
References
Related Vulnerabilities
WordPress Plugin Link Log-external link click monitor SQL Injection (2.0)
Drupal Core 5.x Local File Inclusion (5.0 - 5.15)
Jboss EAP CVE-2013-1896 Vulnerability (CVE-2013-1896)
WordPress 3.8.x Cross-Domain Flash Injection Vulnerability (3.8 - 3.8.24)
Internet Information Services Other Vulnerability (CVE-2000-0071)