---
id: CVE-2026-81810
title: >-
  The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not
  perform any capability check on several of its AJAX actions, gating them only
  on an installation-wide secret which it discloses to any user permitted to
  export…
summary: >-
  The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not
  perform any capability check on several of its AJAX actions, gating them only
  on an installation-wide secret which it discloses to any user permitted to
  export…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-269
product: All-in-One WP Migration and Backup
affected:
  - all-in-one_wp_migration_and_backup < 7.111
published: '2026-09-18'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:08:32.830'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81810'
references:
  - url: 'https://wpscan.com/vulnerability/2036592e-09eb-4231-b450-85d8fbc0ba3f/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00462
epssPercentile: 0.37406
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-18T11:08:44.530532Z'
ingestedAt: '2026-09-18T06:36:37.980Z'
---

## Overview

The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability check on several of its AJAX actions, gating them only on an installation-wide secret which it discloses to any user permitted to export the site, allowing such a user to import an arbitrary site archive and gain administrator access. Exploitation requires an administrator to have granted the export capability to a role that does not hold the All-in-One WP Migration and Backup WordPress plugin before 7.111's own import capability, which is not a default configuration.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
