CyberRota Analysis
AI-GeneratedThe All-in-One WP Migration and Backup plugin for WordPress prior to version 7.108 is vulnerable due to insufficient restrictions on its migration import functionality in multisite installations. This flaw allows an administrator of a single subsite to execute arbitrary PHP code, potentially compromising the entire network. WordPress multisite administrators and users of the affected plugin should prioritize updating to mitigate the risk of network-wide exploitation.
Original NVD Description
The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import functionality to network administrators on multisite installations, allowing an administrator of a single subsite to execute arbitrary PHP code across the entire network.